Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 427
Alerts This Week
Warning Icon 1 427

SUSE: 2023:2748-1 Critical Security Update for Nodejs Released Now

suse
Calendar Grey August 24, 2023
Scroller Suse
The SUSE Package Bulletin offers crucial information regarding Python updates aimed at improving overall system protection.
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-SU-2023:3379-1 Released: Tue Aug 22 18:36:01 2023 Summary: Security update for nodejs16 Type: security Severity: important

References

References : 1214150 1214154 1214156 CVE-2023-32002 CVE-2023-32006 CVE-2023-32559

1214150,1214154,1214156,CVE-2023-32002,CVE-2023-32006,CVE-2023-32559

This update for nodejs16 fixes the following issues:

Update to LTS version 16.20.2.

- CVE-2023-32002: Fixed permissions policies bypass via Module._load (bsc#1214150).

- CVE-2023-32006: Fixed permissions policies impersonation using module.constructor.createRequire() (bsc#1214156).

- CVE-2023-32559: Fixed permissions policies bypass via process.binding (bsc#1214154).

The following package changes have been done:

- nodejs16-16.20.2-150400.3.24.1 updated

- npm16-16.20.2-150400.3.24.1 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:2748-1
Container Tags : bci/node:16 , bci/node:16-9.32 , bci/nodejs:16 , bci/nodejs:16-9.32
Container Release : 9.32
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.