Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Red Hat: RHSA-2022-6985-01 Moderate: Node.js 14 Security Fixes Released

red hat
Calendar Grey October 18, 2022
Dist Redhat Esm H88
Node.js version 14 has a new update on Red Hat Enterprise Linux that resolves several moderate security vulnerabilities and introduces various bug fixes.
An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* nodejs: DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212)
* nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding (CVE-2022-32213)
* nodejs: HTTP request smuggling due to improper delimiting of header fields (CVE-2022-32214)
* nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (CVE-2022-32215)
* got: missing verification of requested URLs allows redirects to UNIX sockets (CVE-2022-33987)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* nodejs:14/nodejs: rebase to latest upstream release (BZ#2106368)
* nodejs:14/nodejs: Specify --with-default-icu-data-dir when using bootstrap build (BZ#2111419)

References

https://access.redhat.com/security/cve/CVE-2022-32212 https://access.redhat.com/security/cve/CVE-2022-32213 https://access.redhat.com/security/cve/CVE-2022-32214 https://access.redhat.com/security/cve/CVE-2022-32215 https://access.redhat.com/security/cve/CVE-2022-33987 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Enterprise Linux AppStream EUS (v.8.4):
Source: nodejs-14.20.0-2.module+el8.4.0+16234+70f4adc8.src.rpm nodejs-nodemon-2.0.19-2.module+el8.4.0+16234+70f4adc8.src.rpm nodejs-packaging-23-3.module+el8.3.0+6519+9f98ed83.src.rpm
aarch64: nodejs-14.20.0-2.module+el8.4.0+16234+70f4adc8.aarch64.rpm nodejs-debuginfo-14.20.0-2.module+el8.4.0+16234+70f4adc8.aarch64.rpm nodejs-debugsource-14.20.0-2.module+el8.4.0+16234+70f4adc8.aarch64.rpm nodejs-devel-14.20.0-2.module+el8.4.0+16234+70f4adc8.aarch64.rpm nodejs-full-i18n-14.20.0-2.module+el8.4.0+16234+70f4adc8.aarch64.rpm npm-6.14.17-1.14.20.0.2.module+el8.4.0+16234+70f4adc8.aarch64.rpm
noarch: nodejs-docs-14.20.0-2.module+el8.4.0+16234+70f4adc8.noarch.rpm nodejs-nodemon-2.0.19-2.module+el8.4.0+16234+70f4adc8.noarch.rpm nodejs-packaging-23-3.module+el8.3.0+6519+9f98ed83.noarch.rpm
ppc64le: nodejs-14.20.0-2.module+el8.4.0+16234+70f4adc8.ppc64le.rpm nodejs-debuginfo-14.20.0-2.module+el8.4.0+16234+70f4adc8.ppc64le.rpm nodejs-debugsource-14.20.0-2.module+el8.4.0+16234+70f4adc8.ppc64le.rpm nodejs-devel-14.20.0-2.module+el8.4.0+16234+70f4adc8.ppc64le.rpm nodejs-full-i18n-14.20.0-2.module+el8.4.0+16234+70f4adc8.ppc64le.rpm npm-6.14.17-1.14.20.0.2.module+el8.4.0+16234+70f4adc8.ppc64le.rpm
s390x:

Read the Full Advisory


Advisory ID: RHSA-2022:6985-01
Product: Red Hat Enterprise Linux
Issue date: 2022-10-18

Topic

An update for the nodejs:14 module is now available for Red Hat EnterpriseLinux 8.4 Extended Update Support.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, noarch, ppc64le, s390x, x86_64

Bugs Fixed

2102001 - CVE-2022-33987 nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets

2105422 - CVE-2022-32212 nodejs: DNS rebinding in --inspect via invalid IP addresses

2105426 - CVE-2022-32215 nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding

2105428 - CVE-2022-32214 nodejs: HTTP request smuggling due to improper delimiting of header fields

2105430 - CVE-2022-32213 nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding

2106368 - nodejs:14/nodejs: rebase to latest upstream release [rhel-8.4.0.z]

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here