Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2023:2748-1 Critical Security Update for Nodejs Released Now

suse
Calendar Grey August 24, 2023
Dist Suse Esm H88
The SUSE Package Bulletin offers crucial information regarding Python updates aimed at improving overall system protection.
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-SU-2023:3379-1 Released: Tue Aug 22 18:36:01 2023 Summary: Security update for nodejs16 Type: security Severity: important

References

References : 1214150 1214154 1214156 CVE-2023-32002 CVE-2023-32006 CVE-2023-32559

1214150,1214154,1214156,CVE-2023-32002,CVE-2023-32006,CVE-2023-32559

This update for nodejs16 fixes the following issues:

Update to LTS version 16.20.2.

- CVE-2023-32002: Fixed permissions policies bypass via Module._load (bsc#1214150).

- CVE-2023-32006: Fixed permissions policies impersonation using module.constructor.createRequire() (bsc#1214156).

- CVE-2023-32559: Fixed permissions policies bypass via process.binding (bsc#1214154).

The following package changes have been done:

- nodejs16-16.20.2-150400.3.24.1 updated

- npm16-16.20.2-150400.3.24.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:2748-1
Container Tags : bci/node:16 , bci/node:16-9.32 , bci/nodejs:16 , bci/nodejs:16-9.32
Container Release : 9.32
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here