Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Node20 Externals Version needs upgrade [CVE-2025-23083, CVE-2025-2309] #3685

Open
rcarpio-hbo opened this issue Jan 29, 2025 · 1 comment
Open
Labels
bug Something isn't working

Comments

@rcarpio-hbo
Copy link

rcarpio-hbo commented Jan 29, 2025

Describe the bug
Security scanning of the default installation method results in:

To Reproduce
Steps to reproduce the behavior:

  • Take latest installation from releases including runtimes and externals. Example: actions-runner-linux-x64-2.322.0.tar.gz
  • Uncompress
  • Run security scan (e.g. Wiz)
  • Expected behavior
  • Clean security report

Runner Version and Platform

v2.322.0

OS of the machine running the runner? OSX/Windows/Linux/...

Linux

What's not working?

CPE vulnerabilities:
    Name: cpe:2.3:a:nodejs:node.js, Version: 20.18.0, Path: /externals/node20/bin/node
        CVE-2025-23083, Severity: HIGH, Source: https://vulncheck.com/browse/cve/CVE-2025-23083
            🩹 Fixed version: 20.18.2
        CVE-2025-23090, Severity: HIGH, Source: https://vulncheck.com/browse/cve/CVE-2025-23090
            🩹 Fixed version: 20.18.2

Vulnerable packages: CRITICAL: 0, HIGH: 1, MEDIUM: 0, LOW: 0, INFORMATIONAL: 0
    Total: 1
Vulnerabilities: CRITICAL: 0, HIGH: 2, MEDIUM: 0, LOW: 0, INFORMATIONAL: 0
    Total: 2, out of which 2 are fixable
Directories scanned: 1053, Files scanned: 4568
Scan results: PASSED. Directory meets policy requirements
@rcarpio-hbo rcarpio-hbo added the bug Something isn't working label Jan 29, 2025
@rcarpio-hbo
Copy link
Author

This issues is duplicated by #3681

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant