Node.js developers fix severe bug that could allow to crash apps
Node.js has released updates for a high severity vulnerability that could be exploited by attackers to corrupt the process and cause unexpected behaviors, such as application crashes and potentially remote code execution (RCE). It is a use-after-free vulnerability, tracked as CVE-2021-22930. The fixes landed in the latest Node.js release 16.6.0 and were also backported to versions 12.22.4 (LTS) and 14.17.4 (LTS).
Source: bleepingcomputer.com
05 August 2021