Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2022:255-1 Important: bci/nodejs Security Advisory Update

suse
Calendar Grey March 6, 2022
Dist Suse Esm H88
The security enhancement for bci/python introduces critical fixes for vulnerabilities found in Python environments and modules.
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-SU-2022:657-1 Released: Wed Mar 2 10:11:51 2022 Summary: Security update for nodejs12 Type: security Severity: important

References

References : 1191962 1191963 1192153 1192154 1192696 CVE-2021-23343 CVE-2021-32803

CVE-2021-32804 CVE-2021-3807 CVE-2021-3918

1191962,1191963,1192153,1192154,1192696,CVE-2021-23343,CVE-2021-32803,CVE-2021-32804,CVE-2021-3807,CVE-2021-3918

This update for nodejs12 fixes the following issues:

- CVE-2021-23343: Fixed ReDoS via splitDeviceRe, splitTailRe and splitPathRe (bsc#1192153).

- CVE-2021-32803: Fixed insufficient symlink protection in node-tar allowing arbitrary file creation and overwrite (bsc#1191963).

- CVE-2021-32804: Fixed insufficient absolute path sanitization in node-tar allowing arbitrary file creation and overwrite (bsc#1191962).

- CVE-2021-3918: Fixed improper controlled modification of object prototype attributes in json-schema (bsc#1192696).

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:255-1
Container Tags : bci/node:12 , bci/node:12-11.15 , bci/nodejs:12 , bci/nodejs:12-11.15
Container Release : 11.15
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here