- Description
- This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node.js. These versions are no longer supported and do not receive updates, including security patches. The continued use of EOL versions may expose systems to potential security risks due to unaddressed software vulnerabilities or dependencies (CWE-1104: Use of Unmaintained Third-Party Components). NOTE: use of the CVE List to report that a product is unsupported, without reference to a specific defect, is novel and the CVE Program is actively assessing both the validity and potential value of this approach. Users are advised to upgrade to actively supported versions of Node.js to ensure continued security updates and support.
- Source
- support@hackerone.com
- NVD status
- Awaiting Analysis
- CNA Tags
- disputed
CVSS 3.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-1104
- Hype score
- Not currently trending
Here's where CVEs jumped the shark... CVEs just because the software/library is End of Life... sure why not 📷 Three for Node: CVE-2025-23088 , CVE-2025-23089 , CVE-2025-23087 Time to dump CVEs and their misleading CVSS severity scoring that does more harm than good. https://t.
@kcqon
24 Jan 2025
198 Impressions
0 Retweets
4 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-23087 This CVE has been issued to inform users that they are using End-of-Life (EOL) versions of Node.js. These versions are no longer supported and do not receive updates,… https://t.co/aBVOkBo2X6
@CVEnew
22 Jan 2025
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes