The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2022:4711 advisory.
– nodejs-trim-off-newlines: ReDoS via string processing (CVE-2021-23425)
– normalize-url: ReDoS for data URLs (CVE-2021-33502)
– nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)
– jquery-ui: XSS in the altField option of the datepicker widget (CVE-2021-41182)
– jquery-ui: XSS in *Text options of the datepicker widget (CVE-2021-41183)
– jquery-ui: XSS in the ‘of’ option of the .position() util (CVE-2021-41184)
Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More