Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 37: 2023-6b866fbe84 High Severity Node.js Policy Bypass

fedora
Calendar Grey July 19, 2023
Dist Fedora Esm H88
Fedora has released an important upgrade for Node.js version 18.16.1, addressing security vulnerabilities including policy circumvention and elevation of privileges.
## 2023-06-20, Version 18.16.1 'Hydrogen' (LTS), @RafaelGSS This is a security release

Summary

Node.js is a platform built on Chrome's JavaScript runtime \

for easily building fast, scalable network applications. \

Node.js uses an event-driven, non-blocking I/O model that \

makes it lightweight and efficient, perfect for data-intensive \

real-time applications that run across distributed devices.}

## 2023-06-20, Version 18.16.1 'Hydrogen' (LTS), @RafaelGSS This is a security

release. ### Notable Changes The following CVEs are fixed in this release: *

[CVE-2023-30581](https://www.cve.org/CVERecord?id=CVE-2023-30581):

`mainModule.__proto__` Bypass Experimental Policy Mechanism (High) *

[CVE-2023-30585](https://www.cve.org/CVERecord?id=CVE-2023-30585):

Privilege escalation via Malicious Registry Key manipulation during Node.js

installer repair process (Medium) * [CVE-2023-30588](https://www.cve.org/CVERecord?id=CVE-2023-30588): Process interuption due to invalid Public

Key information in x509 certificates (Medium) *

[CVE-2023-30589](https://www.cve.org/CVERecord?id=CVE-2023-30589):

HTTP Request Smuggling via Empty headers separated by CR (Medium) *

[CVE-2023-30590](https://www.cve.org/CVERecord?id=CVE-2023-30590):

DiffieHellman does not generate keys after setting a private key (Medium) *

OpenSSL Security Releases * [OpenSSL security advisory 28th

March](https://openssl-library.org/news/secadv/20230328.txt). * [OpenSSL security

advisory 20th April](https://openssl-library.org/news/secadv/20230420.txt). *

[OpenSSL security advisory 30th

May](https://openssl-library.org/news/secadv/20230530.txt) * c-ares vulnerabilities:

* [GHSA-9g78-jv2r-p7vc](https://github.com/c-ares/c-ares/security/advisories/GHSA-9g78-jv2r-p7vc) * [GHSA-8r8p-23f3-64c2](https://github.com/c-ares/c-ares/security/advisories/GHSA-8r8p-23f3-64c2)

* [GHSA-54xr-f67r-4pc4](https://github.com/c-ares/c-ares/security/advisories/GHSA-54xr-f67r-4pc4) * [GHSA-x6mf-cxr9-8q6v](https://github.com/c-ares/c-ares/security/advisories/GHSA-x6mf-cxr9-8q6v) More detailed information on each of the vulnerabilities can be

found in [June 2023 Security

Releases](https://nodejs.org/en/blog/vulnerability/june-2023-security-releases/)

blog post.

* Wed Jun 21 2023 Stephen Gallagher - 1:18.16.1-1

- Update to security release 18.16.1

* Wed Jun 21 2023 Stephen Gallagher - 1:18.16.0-10

- sources: install jinja2 if needed

* Mon May 15 2023 Stephen Gallagher - 1:18.16.0-9

- Fix NPM Obsoletes

su -c 'dnf upgrade --advisory FEDORA-2023-6b866fbe84' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Product: Fedora 37
Version: 18.16.1
Release: 1.fc37
Summary: JavaScript runtime

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here