[FEDORA-2024-e28ccc9c17] Fedora 39: nodejs20
2024-04-03, Version 20.12.1 'Iron' (LTS), @RafaelGSS
This is a security release
Notable Changes
CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session()
leads to HTTP/2 server crash- (High)
CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation -
(Medium)
llhttp version 9.2.1
undici version 5.28.4
Commits
[bd8f10a257] - deps: update undici to v5.28.4 (Matteo Collina) nodejs-
private/node-private#576
[5e34540a96] - http: do not allow OBS fold in headers by default (Paolo Insogna)
nodejs-private/node-private#557
[ba1ae6d188] - src: ensure to close stream when destroying session (Anna
Henningsen) nodejs-private/node-private#561
2024-04-03, Version 20.12.1 'Iron' (LTS), @RafaelGSS
This is a security release
Notable Changes
CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session()
leads to HTTP/2 server crash- (High)
CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation -
(Medium)
llhttp version 9.2.1
undici version 5.28.4
Package | Affected Version |
---|---|
pkg:rpm/fedora/nodejs20?distro=fedora-39 | < 20.12.2.1.fc39 |
- ID
- FEDORA-2024-e28ccc9c17
- Severity
- high
- Severity from
- CVE-2024-27983
- URL
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-e28ccc9c17
- Published
-
2024-04-20T01:03:33
(5 months ago) - Modified
-
2024-04-20T01:03:33
(5 months ago) - Rights
- Copyright 2024 Red Hat, Inc.
- Other Advisories
-
- ALPINE:CVE-2024-27982
- ALPINE:CVE-2024-27983
- ALSA-2024:2778
- ALSA-2024:2779
- ALSA-2024:2780
- ALSA-2024:2853
- ALSA-2024:2910
- ELSA-2024-2778
- ELSA-2024-2779
- ELSA-2024-2780
- ELSA-2024-2853
- ELSA-2024-2910
- FEDORA-2024-2f15e6e876
- FEDORA-2024-2ffe03eaa6
- FEDORA-2024-5dc487ee89
- FEDORA-2024-f83b123d63
- RHSA-2024:2778
- RHSA-2024:2779
- RHSA-2024:2780
- RHSA-2024:2853
- RHSA-2024:2910
- RLSA-2024:2910
- SUSE-SU-2024:1301-1
- SUSE-SU-2024:1305-1
- SUSE-SU-2024:1306-1
- SUSE-SU-2024:1307-1
- SUSE-SU-2024:1308-1
- SUSE-SU-2024:1309-1
- SUSE-SU-2024:1346-1
- SUSE-SU-2024:1355-1
- VU:421644
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 2272764 | Bug #2272764 - CVE-2024-27983 nodejs: CONTINUATION frames DoS | https://bugzilla.redhat.com/show_bug.cgi?id=2272764 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/fedora/nodejs20?distro=fedora-39 | fedora | nodejs20 | < 20.12.2.1.fc39 | fedora-39 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |