Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:0549

Опубликовано: 16 фев. 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: nodejs:12 security update

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

The following packages have been upgraded to a later upstream version: nodejs (12.20.1), nodejs-nodemon (2.0.3).

Security Fix(es):

  • nodejs-mixin-deep: prototype pollution in function mixin-deep (CVE-2019-10746)

  • nodejs-set-value: prototype pollution in function set-value (CVE-2019-10747)

  • nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)

  • nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)

  • nodejs: use-after-free in the TLS implementation (CVE-2020-8265)

  • nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
nodejs-nodemonnoarch1.module+el8.6.0+982+9fdca2d4nodejs-nodemon-2.0.3-1.module+el8.6.0+982+9fdca2d4.noarch.rpm
nodejs-packagingnoarch3.module+el8.3.0+101+f84c7154nodejs-packaging-17-3.module+el8.3.0+101+f84c7154.noarch.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 4 лет назад

ELSA-2021-0549: nodejs:12 security update (MODERATE)

CVSS3: 9.8
ubuntu
почти 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 4.2
redhat
около 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 9.8
nvd
почти 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

CVSS3: 9.8
debian
почти 7 лет назад

The utilities function in all versions <= 0.5.0 of the deep-extend nod ...