Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat: RHSA-2023-0612-01 Moderate: rh-nodejs14-nodejs Security Update

red hat
Calendar Grey February 6, 2023
Dist Redhat Esm H88
Cautious security bulletin regarding rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon outlines important improvements and resolutions.
An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.21.1), rh-nodejs14-nodejs-nodemon (2.0.20). (BZ#2129806, BZ#2135519, BZ#2135520, BZ#2141022)
Security Fix(es):
* glob-parent: Regular Expression Denial of Service (CVE-2021-35065)
* minimist: prototype pollution (CVE-2021-44906)
* node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* express: "qs" prototype poisoning causes the hang of the node process (CVE-2022-24999)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* rh-nodejs14-nodejs: Provide full-i18n subpackage (BZ#2009880)

References

https://access.redhat.com/security/cve/CVE-2021-35065 https://access.redhat.com/security/cve/CVE-2021-44906 https://access.redhat.com/security/cve/CVE-2022-0235 https://access.redhat.com/security/cve/CVE-2022-3517 https://access.redhat.com/security/cve/CVE-2022-24999 https://access.redhat.com/security/cve/CVE-2022-43548 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-nodejs14-nodejs-14.21.1-3.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.20-2.el7.src.rpm
noarch: rh-nodejs14-nodejs-docs-14.21.1-3.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.20-2.el7.noarch.rpm
ppc64le: rh-nodejs14-nodejs-14.21.1-3.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.21.1-3.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.21.1-3.el7.ppc64le.rpm rh-nodejs14-nodejs-full-i18n-14.21.1-3.el7.ppc64le.rpm rh-nodejs14-npm-6.14.17-14.21.1.3.el7.ppc64le.rpm
s390x: rh-nodejs14-nodejs-14.21.1-3.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.21.1-3.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.21.1-3.el7.s390x.rpm rh-nodejs14-nodejs-full-i18n-14.21.1-3.el7.s390x.rpm rh-nodejs14-npm-6.14.17-14.21.1.3.el7.s390x.rpm
x86_64: rh-nodejs14-nodejs-14.21.1-3.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.21.1-3.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.21.1-3.el7.x86_64.rpm rh-nodejs14-nodejs-full-i18n-14.21.1-3.el7.x86_64.rpm rh-nodejs14-npm-6.14.17-14.21.1.3.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-nodejs14-nodejs-14.21.1-3.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.20-2.el7.src.rpm
noarch: rh-nodejs14-nodejs-docs-14.21.1-3.el7.noarch.rpm

Read the Full Advisory


Advisory ID: RHSA-2023:0612-01
Product: Red Hat Software Collections
Issue date: 2023-02-06

Topic

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is nowavailable for Red Hat Software Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

Bugs Fixed

2009880 - rh-nodejs14-nodejs: Provide full-i18n subpackage

2044591 - CVE-2022-0235 node-fetch: exposure of sensitive information to an unauthorized actor

2066009 - CVE-2021-44906 minimist: prototype pollution

2129806 - rh-nodejs14-nodejs: Rebase to the latest Nodejs 14 release [rhscl-3]

2134609 - CVE-2022-3517 nodejs-minimatch: ReDoS via the braceExpand function

2140911 - CVE-2022-43548 nodejs: DNS rebinding in inspect via invalid octal IP address

2150323 - CVE-2022-24999 express: "qs" prototype poisoning causes the hang of the node process

2156324 - CVE-2021-35065 glob-parent: Regular Expression Denial of Service

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here