Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 20.04 LTS: USN-6158-1 Critical Node Fetch Information Exposure

Ubuntu Large Esm H500
Node Fetch could be made to expose sensitive information if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-6158-1
June 13, 2023

node-fetch vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)

Summary:

Node Fetch could be made to expose sensitive information if it opened a
specially crafted file.

Software Description:
- node-fetch: A light-weight module that brings the Fetch API to Node.js

Details:

It was discovered that Node Fetch incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
   node-fetch                      1.7.3-2ubuntu0.1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
   node-fetch                      1.7.3-1ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6158-1
   CVE-2022-0235

Package Information:
   https://launchpad.net/ubuntu/+source/node-fetch/1.7.3-2ubuntu0.1

Ubuntu 20.04 LTS: USN-6158-1 Critical Node Fetch Information Exposure

ubuntu
Calendar Grey June 13, 2023
Dist Ubuntu Esm H88
The Fetch API exhibits a security flaw that could expose confidential information on Ubuntu platforms. It's crucial to perform an update immediately to safeguard your environment.
Node Fetch could be made to expose sensitive information if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: node-fetch 1.7.3-2ubuntu0.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): node-fetch 1.7.3-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6158-1

CVE-2022-0235

Severity
critical
Lowest
Low
Medium
High
Critical

June 13, 2023

Package Information

https://launchpad.net/ubuntu/+source/node-fetch/1.7.3-2ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here