CVE-2022-24999

medium
Published 2022-11-27 · Modified 2023-01-10
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk
5.5

Description

Moderate: nodejs:14 security, bug fix, and enhancement update

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-0050.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2150323

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2140911

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2134609

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2066009

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2044591

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:0050

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-24999

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:0050

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
debian debianbookwormfixed6.10.3+ds+~6.9.7-1
debian debianbullseyefixed6.9.4+ds-1+deb11u1
debian debianforkyfixed6.10.3+ds+~6.9.7-1
debian debiansidfixed6.10.3+ds+~6.9.7-1
debian debiantrixiefixed6.10.3+ds+~6.9.7-1

Package impact

EcosystemPackageVulnerableFixed
npm npmqs>=6.10.0,<6.10.36.10.3
npm npmqs>=6.9.0,<6.9.76.9.7
npm npmqs>=6.8.0,<6.8.36.8.3
npm npmqs>=6.7.0,<6.7.36.7.3
npm npmqs>=6.6.0,<6.6.16.6.1
npm npmqs>=6.5.0,<6.5.36.5.3
npm npmqs>=6.4.0,<6.4.16.4.1
npm npmqs>=6.3.0,<6.3.36.3.3
npm npmqs<6.2.46.2.4

References

Verify integrity in audit chain (admin only). AS-IS.