Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-5814

Опубликовано: 26 авг. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-5814: nodejs:20 security update (MODERATE)

nodejs [1:20.16.0-1]

  • Update to 20.16.0 Fixes: CVE-2024-36137 CVE-2024-22018 CVE-2024-22020

nodejs-nodemon nodejs-packaging

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module nodejs:20 is enabled

nodejs

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-devel

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-docs

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-full-i18n

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-nodemon

3.0.1-1.module+el8.9.0+90082+b6a613a6

nodejs-packaging

2021.06-4.module+el8.9.0+90082+b6a613a6

nodejs-packaging-bundler

2021.06-4.module+el8.9.0+90082+b6a613a6

npm

10.8.1-1.20.16.0.1.module+el8.10.0+90391+162fb07b

Oracle Linux x86_64

Module nodejs:20 is enabled

nodejs

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-devel

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-docs

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-full-i18n

20.16.0-1.module+el8.10.0+90391+162fb07b

nodejs-nodemon

3.0.1-1.module+el8.9.0+90082+b6a613a6

nodejs-packaging

2021.06-4.module+el8.9.0+90082+b6a613a6

nodejs-packaging-bundler

2021.06-4.module+el8.9.0+90082+b6a613a6

npm

10.8.1-1.20.16.0.1.module+el8.10.0+90391+162fb07b

Связанные уязвимости

oracle-oval
10 месяцев назад

ELSA-2024-5815: nodejs:20 security update (MODERATE)

suse-cvrf
11 месяцев назад

Security update for nodejs20

suse-cvrf
11 месяцев назад

Security update for nodejs20

CVSS3: 2.9
ubuntu
11 месяцев назад

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 2.9
redhat
11 месяцев назад

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.