Описание
ELSA-2024-1688: nodejs:20 security update (IMPORTANT)
nodejs [1:20.11.1-1]
- Rebase to version 20.11.1
- Fixes: CVE-2024-21892 CVE-2024-21896 CVE-2024-22017 CVE-2024-22019 (high)
- Fixes: CVE-2023-46809 CVE-2024-21890 CVE-2024-21891 (medium)
nodejs-nodemon nodejs-packaging
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
Module nodejs:20 is enabled
nodejs
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-devel
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-docs
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-full-i18n
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-nodemon
3.0.1-1.module+el9.3.0+90066+12d4a8d7
nodejs-packaging
2021.06-4.module+el9.3.0+90066+12d4a8d7
nodejs-packaging-bundler
2021.06-4.module+el9.3.0+90066+12d4a8d7
npm
10.2.4-1.20.11.1.1.module+el9.3.0+90254+3f4d3ee1
Oracle Linux x86_64
Module nodejs:20 is enabled
nodejs
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-devel
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-docs
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-full-i18n
20.11.1-1.module+el9.3.0+90254+3f4d3ee1
nodejs-nodemon
3.0.1-1.module+el9.3.0+90066+12d4a8d7
nodejs-packaging
2021.06-4.module+el9.3.0+90066+12d4a8d7
nodejs-packaging-bundler
2021.06-4.module+el9.3.0+90066+12d4a8d7
npm
10.2.4-1.20.11.1.1.module+el9.3.0+90254+3f4d3ee1
Ссылки на источники
Связанные уязвимости
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.