Important: nodejs:14 security, bug fix, and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1743", "synopsis": "Important: nodejs:14 security, bug fix, and enhancement update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs, nodejs-packaging, module.nodejs-packaging, module.nodejs-nodemon, nodejs-nodemon, module.nodejs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nThe following packages have been upgraded to a later upstream version: nodejs (14.21.3).\n\nSecurity Fix(es):\n\n* decode-uri-component: improper input validation resulting in DoS (CVE-2022-38900)\n\n* glob-parent: Regular Expression Denial of Service (CVE-2021-35065)\n\n* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)\n\n* c-ares: buffer overflow in config_sortlist() due to missing string length check (CVE-2022-4904)\n\n* http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability (CVE-2022-25881)\n\n* Node.js: Permissions policies can be bypassed via process.mainModule (CVE-2023-23918)\n\n* Node.js: insecure loading of ICU data through ICU_DATA environment variable (CVE-2023-23920)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2134609", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2134609", "description": ""}, {"ticket": "2156324", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2156324", "description": ""}, {"ticket": "2165824", "sourceBy": "Red Hat","sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2165824", "description": ""}, {"ticket": "2168631", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2168631", "description": ""}, {"ticket": "2170644", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2170644", "description": ""}, {"ticket": "2171935", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2171935", "description": ""}, {"ticket": "2172217", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2172217", "description": ""}, {"ticket": "2175826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2175826", "description": ""}], "cves": [{"name": "CVE-2021-35065", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-35065", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-25881", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-25881", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-3517", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-3517", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-38900", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-38900", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-4904", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-4904", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-23918", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23918", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-23920", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23920","cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-04-26T15:28:13.052501Z", "rpms": {"Rocky Linux 8": {"nvras": ["nodejs-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.aarch64.rpm", "nodejs-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.src.rpm", "nodejs-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.x86_64.rpm", "nodejs-debuginfo-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.aarch64.rpm", "nodejs-debuginfo-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.x86_64.rpm", "nodejs-debugsource-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.aarch64.rpm", "nodejs-debugsource-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.x86_64.rpm", "nodejs-devel-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.aarch64.rpm", "nodejs-devel-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.x86_64.rpm", "nodejs-docs-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.noarch.rpm", "nodejs-full-i18n-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.aarch64.rpm", "nodejs-full-i18n-1:14.21.3-1.module+el8.7.0+1183+c2c35f0a.x86_64.rpm", "nodejs-nodemon-0:2.0.20-3.module+el8.7.0+1178+d52dba78.noarch.rpm", "nodejs-nodemon-0:2.0.20-3.module+el8.7.0+1178+d52dba78.src.rpm", "nodejs-packaging-0:23-3.module+el8.7.0+1071+4bdda2a8.noarch.rpm", "nodejs-packaging-0:23-3.module+el8.7.0+1071+4bdda2a8.src.rpm", "npm-1:6.14.18-1.14.21.3.1.module+el8.7.0+1183+c2c35f0a.aarch64.rpm", "npm-1:6.14.18-1.14.21.3.1.module+el8.7.0+1183+c2c35f0a.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Node.js 14 undergoes major enhancements targeting vulnerabilities and essential patches to bolster system reliability.. Nodejs Security Update, Rocky Linux Advisory, Nodejs Bug Fixes, Nodejs Enhancements, Nodejs Security Issues. . Severity: Important. LinuxSecurity.com Team
tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources (CVE-2018-1304) * tomcat: Late application of security constraints can lead to resource exposure for unauthorised users (CVE-2018-1305) * tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014) * tomcat: Host name verification miss [More...]. Synopsis: Moderate: tomcat security, bug fix, and enhancement update Advisory ID: SLSA-2019:2205-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-1305 CVE-2018-1304 CVE-2018-8034 CVE-2018-8014 -- Security Fix(es): * tomcat: Incorrect handling of empty string URL in security constraints can lead to unintended exposure of resources (CVE-2018-1304) * tomcat: Late application of security constraints can lead to resource exposure for unauthorised users (CVE-2018-1305) * tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014) * tomcat: Host name verification missing in WebSocket client (CVE-2018-8034) -- SL7 x86_64 tomcat-7.0.76-9.el7.noarch.rpm tomcat-jsp-2.2-api-7.0.76-9.el7.noarch.rpm tomcat-admin-webapps-7.0.76-9.el7.noarch.rpm tomcat-el-2.2-api-7.0.76-9.el7.noarch.rpm tomcat-servlet-3.0-api-7.0.76-9.el7.noarch.rpm tomcat-lib-7.0.76-9.el7.noarch.rpm tomcat-webapps-7.0.76-9.el7.noarch.rpm tomcat-docs-webapp-7.0.76-9.el7.noarch.rpm tomcat-javadoc-7.0.76-9.el7.noarch.rpm tomcat-jsvc-7.0.76-9.el7.noarch.rpm noarch tomcat-servlet-3.0-api-7.0.76-9.el7.noarch.rpm tomcat-7.0.76-9.el7.noarch.rpm tomcat-admin-webapps-7.0.76-9.el7.noarch.rpm tomcat-docs-webapp-7.0.76-9.el7.noarch.rpm tomcat-el-2.2-api-7.0.76-9.el7.noarch.rpm tomcat-javadoc-7.0.76-9.el7.noarch.rpm tomcat-jsp-2.2-api-7.0.76-9.el7.noarch.rpm tomcat-jsvc-7.0.76-9.el7.noarch.rpm tomcat-lib-7.0.76-9.el7.noarch.rpm tomcat-webapps-7.0.76-9.el7.noarch.rpm -Scientific Linux Development Team . Caution: Tomcat security notice regarding vulnerabilities and resolutions for SL7.x. Safeguard your system with the latest patches.. Tomcat Security, Resource Exposure, Security Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.