[FEDORA-2023-f66fc0f62a] Fedora 37: nodejs20

Severity Critical
Affected Packages 1
CVEs 6

2023-10-13, Version 20.8.1 (Current), @RafaelGSS This is a security release.

Notable Changes The following CVEs are fixed in this release: *

CVE-2023-44487:
nghttp2 Security Release (High) * CVE-2023-45143: undici Security Release (High) *
CVE-2023-39332:
Path traversal through path stored in Uint8Array (High) *
CVE-2023-39331:
Permission model improperly protects against path traversal (High) *
CVE-2023-38552:
Integrity checks according to policies can be circumvented (Medium) *
CVE-2023-39333:
Code injection via WebAssembly export names (Low) More detailed information on
each of the vulnerabilities can be found in October 2023 Security
Releases
blog post.

Package Affected Version
pkg:rpm/fedora/nodejs20?distro=fedora-37 < 20.8.1.1.fc37
ID
FEDORA-2023-f66fc0f62a
Severity
critical
Severity from
CVE-2023-39332
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2023-f66fc0f62a
Published
2023-10-26T01:35:05
(10 months ago)
Modified
2023-10-26T01:35:05
(10 months ago)
Rights
Copyright 2023 Red Hat, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/nodejs20?distro=fedora-37 fedora nodejs20 < 20.8.1.1.fc37 fedora-37
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...