First published: Wed Jul 05 2023(Updated: )
Last updated 24 July 2024
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | <=2.0 | |
Nodejs Node.js | >=16.0.0<16.20.1 | |
Nodejs Node.js | >=18.0.0<18.16.1 | |
Nodejs Node.js | >=20.0.0<20.3.1 | |
debian/nodejs | <=12.22.12~dfsg-1~deb11u4 | 12.22.12~dfsg-1~deb11u5 18.19.0+dfsg-6~deb12u2 18.19.0+dfsg-6~deb12u1 20.17.0+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30590 is a vulnerability that affects the generateKeys() API function returned from crypto.createDiffieHellman() in Node.js.
CVE-2023-30590 allows an attacker to generate missing or outdated keys in Node.js, potentially compromising the security of cryptographic operations.
CVE-2023-30590 has a severity rating of high, with a score of 7.5.
CVE-2023-30590 affects Node.js versions 16.0.0 to 16.20.1, 18.0.0 to 18.16.1, and 20.0.0 to 20.3.1.
To fix CVE-2023-30590, update your Node.js installation to a version that includes the security patch provided by the Node.js team.