Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Oracle Linux 9 ELSA-2023-2655 Critical: Nodejs and Nodemon Security Fix

oracle
Calendar Grey May 18, 2023
Scroller Oracle
The security bulletin ELSA-2023-2655 for Oracle Linux details significant updates and remedial measures for both nodejs and nodemon packages.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

nodejs [1:16.19.1-1] - Rebase to 16.19.1 - Resolves: rhbz#2153714 - Resolves: CVE-2023-23918 CVE-2023-23919 CVE-2023-23936 CVE-2023-24807 CVE-2023-23920 - Resolves: CVE-2022-25881 CVE-2022-4904 nodejs-nodemon [2.0.20-3] - Patch bundled glob-parent - Resolves: CVE-2021-35065

SRPMs

https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-16.19.1-1.el9_2.src.rpm https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-nodemon-2.0.20-3.el9_2.src.rpm

x86_64

nodejs-16.19.1-1.el9_2.x86_64.rpm nodejs-docs-16.19.1-1.el9_2.noarch.rpm nodejs-full-i18n-16.19.1-1.el9_2.x86_64.rpm nodejs-libs-16.19.1-1.el9_2.i686.rpm nodejs-libs-16.19.1-1.el9_2.x86_64.rpm nodejs-nodemon-2.0.20-3.el9_2.noarch.rpm npm-8.19.3-1.16.19.1.1.el9_2.x86_64.rpm

aarch64

nodejs-16.19.1-1.el9_2.aarch64.rpm nodejs-docs-16.19.1-1.el9_2.noarch.rpm nodejs-full-i18n-16.19.1-1.el9_2.aarch64.rpm nodejs-libs-16.19.1-1.el9_2.aarch64.rpm nodejs-nodemon-2.0.20-3.el9_2.noarch.rpm npm-8.19.3-1.16.19.1.1.el9_2.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2022-4904 CVE-2022-25881 CVE-2023-23918 CVE-2023-23920 CVE-2023-23936 CVE-2023-24807

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.