Skip to content

Commit 60bc31c

Browse files
RafaelGSSmhdawson
andauthored
Apply suggestions from code review
Co-authored-by: Michael Dawson <mdawson@devrus.com> Signed-off-by: Rafael Gonzaga <rafael.nunu@hotmail.com>
1 parent a0d95e4 commit 60bc31c

1 file changed

Lines changed: 10 additions & 5 deletions

File tree

apps/site/pages/en/blog/vulnerability/updates-cve-for-end-of-life.md

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,16 @@ layout: blog-post
66
author: Rafael Gonzaga
77
---
88

9-
# Rationale for Issuing CVEs on End-of-Life Node.js Versions
10-
11-
**TL;DR:** CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 have been
12-
rejected by MITRE and therefore the Node.js team decided to update previous
13-
CVEs to cover EOL releases, reflecting their ongoing security risks.
9+
# Update on the issuance of CVEs to mark End-of-Life Node.js Versions
10+
11+
**TL;DR:** CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 issued to
12+
tag EOL versions have been rejected by MITRE.
13+
The Node.js team has, therefore, decided to update previous vulnerability specific
14+
CVEs to cover EOL releases, reflecting their ongoing security risks. This means that
15+
all new CVEs issued will include EOL releases in the applicability until we have specific
16+
information that indicates a CVE does not apply to an EOL release line. The project
17+
does not plan to evaluate CVEs against EOL lines but information provided to the
18+
project may be used to update the applicability if/when it is available.
1419

1520
On January 21, 2025, Node.js released security patches for four active release
1621
lines. At the same time, CVEs were assigned to cover EOL (end-of-life) versions:

0 commit comments

Comments
 (0)