This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node.js. These versions are no longer supported and do not receive updates, including security patches. The continued use of EOL versions may expose systems to potential security risks due to unaddressed software vulnerabilities or dependencies (CWE-1104: Use of Unmaintained Third-Party Components). NOTE: use of the CVE List to report that a product is unsupported, without reference to a specific defect, is novel and the CVE Program is actively assessing both the validity and potential value of this approach. Users are advised to upgrade to actively supported versions of Node.js to ensure continued security updates and support.
History

Mon, 10 Feb 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Feb 2025 02:15:00 +0000

Type Values Removed Values Added
Description This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node.js. These versions are no longer supported and do not receive updates, including security patches. The continued use of EOL versions may expose systems to potential security risks due to unaddressed software vulnerabilities or dependencies (CWE-1104: Use of Unmaintained Third-Party Components). Users are advised to upgrade to actively supported versions of Node.js to ensure continued security updates and support. This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node.js. These versions are no longer supported and do not receive updates, including security patches. The continued use of EOL versions may expose systems to potential security risks due to unaddressed software vulnerabilities or dependencies (CWE-1104: Use of Unmaintained Third-Party Components). NOTE: use of the CVE List to report that a product is unsupported, without reference to a specific defect, is novel and the CVE Program is actively assessing both the validity and potential value of this approach. Users are advised to upgrade to actively supported versions of Node.js to ensure continued security updates and support.

Thu, 23 Jan 2025 22:45:00 +0000

Type Values Removed Values Added
References

Thu, 23 Jan 2025 13:30:00 +0000

Type Values Removed Values Added
Title node.js: End-of-Life Node.js Versions Pose Security Risks 17.x or prior
Weaknesses CWE-1104
References
Metrics threat_severity

None

threat_severity

Important


Wed, 22 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node.js. These versions are no longer supported and do not receive updates, including security patches. The continued use of EOL versions may expose systems to potential security risks due to unaddressed software vulnerabilities or dependencies (CWE-1104: Use of Unmaintained Third-Party Components). Users are advised to upgrade to actively supported versions of Node.js to ensure continued security updates and support.
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-02-10T23:11:30.657Z

Reserved: 2025-01-10T19:05:52.772Z

Link: CVE-2025-23087

cve-icon Vulnrichment

Updated: 2025-01-23T21:20:20.219Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-22T02:15:34.080

Modified: 2025-02-10T23:15:15.717

Link: CVE-2025-23087

cve-icon Redhat

Severity : Important

Publid Date: 2025-01-22T01:11:30Z

Links: CVE-2025-23087 - Bugzilla