<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2018-12120</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2018-12120</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>23</Number>
        <Date>2025-02-17T02:46:22Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T14:14:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-02-17T02:46:22Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2018-12120</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2019-January/005042.html</URL>
      <Description>E-Mail link for SUSE-SU-2019:0117-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2019-February/005121.html</URL>
      <Description>E-Mail link for SUSE-SU-2019:0395-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MCR24YF2JL7BUZULCM3J6PO547A2FBEH/#MCR24YF2JL7BUZULCM3J6PO547A2FBEH</URL>
      <Description>E-Mail link for openSUSE-SU-2019:0088-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TEDLOHSLOHZ36RTEAODDXPLT3YMQBGBI/#TEDLOHSLOHZ36RTEAODDXPLT3YMQBGBI</URL>
      <Description>E-Mail link for openSUSE-SU-2019:0234-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 4">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 4">
        <FullProductName ProductID="SUSE Enterprise Storage 4" CPE="cpe:/o:suse:ses:4">SUSE Enterprise Storage 4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 7.1">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 7.1">
        <FullProductName ProductID="SUSE Enterprise Storage 7.1" CPE="cpe:/o:suse:ses:7.1">SUSE Enterprise Storage 7.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15" CPE="cpe:/o:suse:sle-module-web-scripting:15">SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp3">SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp3">SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15" CPE="cpe:/o:suse:sle-module-web-scripting:15">SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15" CPE="cpe:/o:suse:sle-module-web-scripting:15">SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3" CPE="cpe:/o:suse:sles_sap:15:sp3">SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 4.2">
      <Branch Type="Product Name" Name="SUSE Manager Server 4.2">
        <FullProductName ProductID="SUSE Manager Server 4.2" CPE="cpe:/o:suse:suse-manager-server:4.2">SUSE Manager Server 4.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 7">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 7">
        <FullProductName ProductID="SUSE OpenStack Cloud 7" CPE="cpe:/o:suse:suse-openstack-cloud:7">SUSE OpenStack Cloud 7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud Crowbar 8">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud Crowbar 8">
        <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8" CPE="cpe:/o:suse:suse-openstack-cloud-crowbar:8">SUSE OpenStack Cloud Crowbar 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="nodejs10">
      <FullProductName ProductID="nodejs10" CPE="cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*">nodejs10</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs10-devel">
      <FullProductName ProductID="nodejs10-devel">nodejs10-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs10-docs">
      <FullProductName ProductID="nodejs10-docs">nodejs10-docs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs12">
      <FullProductName ProductID="nodejs12" CPE="cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*">nodejs12</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs12-devel">
      <FullProductName ProductID="nodejs12-devel">nodejs12-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs12-docs">
      <FullProductName ProductID="nodejs12-docs">nodejs12-docs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs4-4.9.1-15.17.1">
      <FullProductName ProductID="nodejs4-4.9.1-15.17.1" CPE="cpe:2.3:a:nodejs:node.js:4.9.1:*:*:*:-:*:*:*">nodejs4-4.9.1-15.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs4-devel-4.9.1-15.17.1">
      <FullProductName ProductID="nodejs4-devel-4.9.1-15.17.1">nodejs4-devel-4.9.1-15.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs4-docs-4.9.1-15.17.1">
      <FullProductName ProductID="nodejs4-docs-4.9.1-15.17.1">nodejs4-docs-4.9.1-15.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs6-6.16.0-11.21.1">
      <FullProductName ProductID="nodejs6-6.16.0-11.21.1" CPE="cpe:2.3:a:nodejs:node.js:6.16.0:*:*:*:-:*:*:*">nodejs6-6.16.0-11.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs6-devel-6.16.0-11.21.1">
      <FullProductName ProductID="nodejs6-devel-6.16.0-11.21.1">nodejs6-devel-6.16.0-11.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs6-docs-6.16.0-11.21.1">
      <FullProductName ProductID="nodejs6-docs-6.16.0-11.21.1">nodejs6-docs-6.16.0-11.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs8">
      <FullProductName ProductID="nodejs8" CPE="cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*">nodejs8</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs8-devel">
      <FullProductName ProductID="nodejs8-devel">nodejs8-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs8-docs">
      <FullProductName ProductID="nodejs8-docs">nodejs8-docs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="npm10">
      <FullProductName ProductID="npm10">npm10</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="npm12">
      <FullProductName ProductID="npm12">npm12</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="npm4-4.9.1-15.17.1">
      <FullProductName ProductID="npm4-4.9.1-15.17.1">npm4-4.9.1-15.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="npm6-6.16.0-11.21.1">
      <FullProductName ProductID="npm6-6.16.0-11.21.1">npm6-6.16.0-11.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="npm8">
      <FullProductName ProductID="npm8">npm8</FullProductName>
    </Branch>
    <Relationship ProductReference="nodejs4-4.9.1-15.17.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:nodejs4-4.9.1-15.17.1">nodejs4-4.9.1-15.17.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs6-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:nodejs6-6.16.0-11.21.1">nodejs6-6.16.0-11.21.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs4-4.9.1-15.17.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.9.1-15.17.1">nodejs4-4.9.1-15.17.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs4-devel-4.9.1-15.17.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.9.1-15.17.1">nodejs4-devel-4.9.1-15.17.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs4-docs-4.9.1-15.17.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.9.1-15.17.1">nodejs4-docs-4.9.1-15.17.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs6-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs6-6.16.0-11.21.1">nodejs6-6.16.0-11.21.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs6-devel-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs6-devel-6.16.0-11.21.1">nodejs6-devel-6.16.0-11.21.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs6-docs-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs6-docs-6.16.0-11.21.1">nodejs6-docs-6.16.0-11.21.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm4-4.9.1-15.17.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.9.1-15.17.1">npm4-4.9.1-15.17.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm6-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:npm6-6.16.0-11.21.1">npm6-6.16.0-11.21.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs6-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:nodejs6-6.16.0-11.21.1">nodejs6-6.16.0-11.21.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs6-6.16.0-11.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:nodejs6-6.16.0-11.21.1">nodejs6-6.16.0-11.21.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 7.1">
      <FullProductName ProductID="SUSE Enterprise Storage 7.1:nodejs12">nodejs12 as a component of SUSE Enterprise Storage 7.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 7.1">
      <FullProductName ProductID="SUSE Enterprise Storage 7.1:nodejs12-devel">nodejs12-devel as a component of SUSE Enterprise Storage 7.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 7.1">
      <FullProductName ProductID="SUSE Enterprise Storage 7.1:nodejs12-docs">nodejs12-docs as a component of SUSE Enterprise Storage 7.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm12" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 7.1">
      <FullProductName ProductID="SUSE Enterprise Storage 7.1:npm12">npm12 as a component of SUSE Enterprise Storage 7.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:nodejs12">nodejs12 as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:nodejs12-devel">nodejs12-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:nodejs12-docs">nodejs12-docs as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:npm12">npm12 as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:nodejs12">nodejs12 as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:nodejs12-devel">nodejs12-devel as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:nodejs12-docs">nodejs12-docs as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:npm12">npm12 as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs10" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs10">nodejs10 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs10-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs10-devel">nodejs10-devel as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs10-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs10-docs">nodejs10-docs as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm10" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:npm10">npm10 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs12">nodejs12 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs12-devel">nodejs12-devel as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs12-docs">nodejs12-docs as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:npm12">npm12 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs8" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15:nodejs8">nodejs8 as a component of SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs8-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15:nodejs8-devel">nodejs8-devel as a component of SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs8-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15:nodejs8-docs">nodejs8-docs as a component of SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm8" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15:npm8">npm8 as a component of SUSE Linux Enterprise Module for Web and Scripting 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3:nodejs12">nodejs12 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3:nodejs12-devel">nodejs12-devel as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3:nodejs12-docs">nodejs12-docs as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm12" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3:npm12">npm12 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.2">
      <FullProductName ProductID="SUSE Manager Server 4.2:nodejs12">nodejs12 as a component of SUSE Manager Server 4.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.2">
      <FullProductName ProductID="SUSE Manager Server 4.2:nodejs12-devel">nodejs12-devel as a component of SUSE Manager Server 4.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs12-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.2">
      <FullProductName ProductID="SUSE Manager Server 4.2:nodejs12-docs">nodejs12-docs as a component of SUSE Manager Server 4.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm12" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.2">
      <FullProductName ProductID="SUSE Manager Server 4.2:npm12">npm12 as a component of SUSE Manager Server 4.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.</Note>
    </Notes>
    <CVE>CVE-2018-12120</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 4:nodejs4-4.9.1-15.17.1</ProductID>
        <ProductID>SUSE Enterprise Storage 4:nodejs6-6.16.0-11.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-4.9.1-15.17.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-devel-4.9.1-15.17.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs4-docs-4.9.1-15.17.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs6-6.16.0-11.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs6-devel-6.16.0-11.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs6-docs-6.16.0-11.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:npm4-4.9.1-15.17.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:npm6-6.16.0-11.21.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:nodejs6-6.16.0-11.21.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:nodejs6-6.16.0-11.21.1</ProductID>
      </Status>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Enterprise Storage 7.1:nodejs12</ProductID>
        <ProductID>SUSE Enterprise Storage 7.1:nodejs12-devel</ProductID>
        <ProductID>SUSE Enterprise Storage 7.1:nodejs12-docs</ProductID>
        <ProductID>SUSE Enterprise Storage 7.1:npm12</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:nodejs12</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:nodejs12-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:nodejs12-docs</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS:npm12</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:nodejs12</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:nodejs12-devel</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:nodejs12-docs</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:npm12</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs12</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs12-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs12-docs</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:npm12</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15:nodejs8</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15:nodejs8-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15:nodejs8-docs</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15:npm8</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP3:nodejs12</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP3:nodejs12-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP3:nodejs12-docs</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP3:npm12</ProductID>
        <ProductID>SUSE Manager Server 4.2:nodejs12</ProductID>
        <ProductID>SUSE Manager Server 4.2:nodejs12-devel</ProductID>
        <ProductID>SUSE Manager Server 4.2:nodejs12-docs</ProductID>
        <ProductID>SUSE Manager Server 4.2:npm12</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.8</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
