DPC:漏洞掃描程式回報 Node.js 和 MongoDB 版本不受支援
Summary: 漏洞掃描器報告 DPC 伺服器執行的 Node.js 或 MongoDB 版本不受支援。
Symptoms
掃描器顯示 Node.js,安裝在 DPC 上的已不受支援。
掃描器顯示 MongoDB,安裝在 DPC 上的已不受支援。
Cause
這是在 DPC 伺服器上執行漏洞掃描程式的結果。
Resolution
產品管理和工程部門已提供有關此問題的下列資訊。
MongDB:
"MongoDB 4.2.x will remain at its current version within our architecture. While MongoDB is out of vendor compatibility/compliance, our multilayered security architecture prevents external attacks: MongoDB is not directly accessible from external networks, protected by firewall rules, and only accessible internally through authenticated application layers. This isolation eliminates direct attack vectors, making the system secure despite EOL status. We continue to provide break/fix support and security patching where applicable and possible."
Node.js:
"We acknowledge Node.js 16.x (v16.20.2) reached End-of-Life. However, our deployment architecture eliminates attack surfaces: Node.js is bundled within the application (not system-wide), production serves only prebuilt static files, Node.js runtime is never exposed to network requests, and the npm package manager is absent in production. This means attackers cannot directly target or exploit Node.js vulnerabilities, making the deployment secure despite EOL status."