Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2022:0114-1 Moderate: Nodejs14 Security Threats Resolved

suse
Calendar Grey January 18, 2022
Dist Suse Esm H88
A new release for nodejs14 has been issued, addressing several moderate security vulnerabilities. Please update without delay!
An update that fixes four vulnerabilities is now available

Summary

This update for nodejs14 fixes the following issues: - CVE-2021-44531: Fixed improper handling of URI Subject Alternative Names (bsc#1194511). - CVE-2021-44532: Fixed certificate Verification Bypass via String Injection (bsc#1194512). - CVE-2021-44533: Fixed incorrect handling of certificate subject and issuer fields (bsc#1194513). - CVE-2022-21824: Fixed prototype pollution via console.table properties (bsc#1194514). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-114=1 Package List:

References

#1194511 #1194512 #1194513 #1194514

Cross- CVE-2021-44531 CVE-2021-44532 CVE-2021-44533

CVE-2022-21824

CVSS scores:

CVE-2021-44531 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2021-44532 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2021-44533 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-21824 (SUSE): 4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

Affected Products:

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2021-44531.html

https://www.suse.com/security/cve/CVE-2021-44532.html

https://www.suse.com/security/cve/CVE-2021-44533.html

https://www.suse.com/security/cve/CVE-2022-21824.html

https://bugzilla.suse.com/1194511

Announcement ID: SUSE-SU-2022:0114-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here