Cryptographic Flaw in Node.js Releases by OpenJS Foundation
CVE-2023-23919
7.5HIGH
What is CVE-2023-23919?
A cryptographic flaw exists in specific Node.js versions that fails to clear the OpenSSL error stack after certain operations. This oversight can lead to misleading error signals in subsequent cryptographic actions conducted on the same thread, creating opportunities that may result in denial of service.
Affected Version(s)
Node 4.0 < 4.*
Node 5.0 < 5.*
Node 6.0 < 6.*