witchcraze / NVD_CHECK

1 stars 0 forks source link

CHK NVD : CVE-2019-9518 - 8f7c43c0 #913

Closed witchcraze closed 1 year ago

witchcraze commented 1 year ago

Update Suggestion - CVE-2019-9518 - Cvss2 : 7.8 Update Suggestion - CVE-2019-9518 - Cvss3 : 7.5

https://github.com/witchcraze/NVD_CHECK/blob/main/Nodejs/CVE-2019-9518.json

- CVE-2019-9518
- Suggested Configration
  - OR
     *cpe:2.3:cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* versions from (including) 10.0.0 up to (excluding) 10.16.3
     *cpe:2.3:cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.8.1
     *cpe:2.3:cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* versions from (including) 8.0.0 up to (excluding) 8.16.1
- Reference
  - https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V10.md
  - https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V12.md
  - https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V8.md
  - https://github.com/nodejs/security-wg/blob/main/vuln/core/62.json
- I Checked
  - XXXX
https://nvd.nist.gov/vuln/detail/CVE-2019-9518 URI Start(Ex) Start(Inc) End(Ex) End(Inc)
cpe:/o:synology:vs960hd_firmware:-
cpe:/o:redhat:enterprise_linux:8.0
cpe:/o:opensuse:leap:15.1
cpe:/o:opensuse:leap:15.0
cpe:/o:fedoraproject:fedora:30
cpe:/o:fedoraproject:fedora:29
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:10.0
cpe:/o:canonical:ubuntu_linux:19.04
cpe:/o:canonical:ubuntu_linux:18.04::lts~
cpe:/o:canonical:ubuntu_linux:16.04::lts~
cpe:/a:synology:skynas:-
cpe:/a:synology:diskstation_manager:6.2
cpe:/a:redhat:software_collections:1.0
cpe:/a:redhat:quay:3.0.0
cpe:/a:redhat:openshift_service_mesh:1.0
cpe:/a:redhat:jboss_enterprise_application_platform:7.3.0
cpe:/a:redhat:jboss_enterprise_application_platform:7.2.0
cpe:/a:redhat:jboss_core_services:1.0
cpe:/a:oracle:graalvm:19.2.0::enterprise~
cpe:/a:mcafee:web_gateway 7.7.2.0 7.7.2.24
cpe:/a:mcafee:web_gateway 7.8.2.0 7.8.2.13
cpe:/a:mcafee:web_gateway 8.1.0 8.2.0
cpe:/a:apple:swiftnio 1.0.0 1.4.0
cpe:/a:apache:traffic_server 6.0.0 6.2.3
cpe:/a:apache:traffic_server 7.0.0 7.1.6
cpe:/a:apache:traffic_server 8.0.0 8.0.3
witchcraze commented 1 year ago
- CVE-2019-9518
- Suggested Configration
  - OR
     *cpe:2.3:cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* versions from (including) 10.0.0 up to (excluding) 10.16.3
     *cpe:2.3:cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.8.1
     *cpe:2.3:cpe:/a:nodejs:node.js:*:*:*:*:*:*:*:* versions from (including) 8.0.0 up to (excluding) 8.16.1
- Reference
  - https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V10.md
  - https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V12.md
  - https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V8.md
  - https://github.com/nodejs/security-wg/blob/main/vuln/core/62.json
- I Checked
  - CVE-2019-9518 is written in each CHANGELOG
  - From 62.json in security-wg, same informatin is written