[FREEBSD:C0C1834C-9761-11EB-ACFD-0022489AD614] Node.js -- April 2021 Security Releases
Severity
Critical
Affected Packages
4
CVEs
3
Node.js reports:
OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High) (CVE-2021-3450)
This is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20210325.txt
OpenSSL - NULL pointer deref in signature_algorithms processing (High) (CVE-2021-3449)
This is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20210325.txt
npm upgrade - Update y18n to fix Prototype-Pollution (High) (CVE-2020-7774)
This is a vulnerability in the y18n npm module which may be exploited by prototype pollution. You can read more about it in https://github.com/advisories/GHSA-c4w7-xm78-47vh
Package | Affected Version |
---|---|
pkg:freebsd/node14 | < 14.16.1 |
pkg:freebsd/node12 | < 12.22.1 |
pkg:freebsd/node10 | < 10.24.1 |
pkg:freebsd/node | < 15.14.0 |
- ID
- FREEBSD:C0C1834C-9761-11EB-ACFD-0022489AD614
- Severity
- critical
- Severity from
- CVE-2020-7774
- URL
- http://vuxml.freebsd.org/freebsd/c0c1834c-9761-11eb-acfd-0022489ad614.html
- Published
-
2021-04-06T00:00:00
(3 years ago) - Modified
-
2021-04-07T00:00:00
(3 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
-
- ALAS2-2021-1622
- ALAS2-2024-2502
- ALPINE:CVE-2020-7774
- ALPINE:CVE-2021-3449
- ALPINE:CVE-2021-3450
- ALSA-2020:5499
- ALSA-2021:0548
- ALSA-2021:0551
- ALSA-2021:1024
- ASA-202103-10
- CISCO-SA-OPENSSL-2021-GHY28DJD
- DSA-4875-1
- ELSA-2020-5499
- ELSA-2021-0548
- ELSA-2021-0551
- ELSA-2021-1024
- ELSA-2021-9151
- FEDORA-2021-cbf14ab8f9
- FREEBSD:38A4A043-E937-11EB-9B84-D4C9EF517024
- FREEBSD:56BA4513-A1BE-11EB-9072-D4C9EF517024
- FREEBSD:5A668AB3-8D86-11EB-B8D6-D4C9EF517024
- GLSA-202103-03
- GLSA-202405-29
- MS:CVE-2021-3449
- MS:CVE-2021-3450
- NPM:GHSA-C4W7-XM78-47VH
- openSUSE-SU-2021:0476-1
- openSUSE-SU-2021:1059-1
- openSUSE-SU-2021:1060-1
- openSUSE-SU-2021:1061-1
- openSUSE-SU-2021:1113-1
- openSUSE-SU-2021:2327-1
- openSUSE-SU-2021:2353-1
- openSUSE-SU-2021:2354-1
- openSUSE-SU-2021:2618-1
- RHSA-2020:5499
- RHSA-2021:0548
- RHSA-2021:0551
- RHSA-2021:1024
- RLSA-2020:5499
- RLSA-2021:0548
- RLSA-2021:0551
- RUSTSEC-2021-0055
- RUSTSEC-2021-0056
- SECADV-20210325-1
- SECADV-20210325-2
- SUSE-SU-2021:0954-1
- SUSE-SU-2021:0955-1
- SUSE-SU-2021:0955-2
- SUSE-SU-2021:2319-1
- SUSE-SU-2021:2323-1
- SUSE-SU-2021:2326-1
- SUSE-SU-2021:2327-1
- SUSE-SU-2021:2353-1
- SUSE-SU-2021:2354-1
- SUSE-SU-2021:2618-1
- SUSE-SU-2021:2620-1
- USN-4891-1
- USN-5038-1
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://nodejs.org/en/blog/vulnerability/april-2021-security-releases/ | ||
FreeBSD VuXML | https://www.openssl.org/news/secadv/20210325.txt | ||
FreeBSD VuXML | https://github.com/advisories/GHSA-c4w7-xm78-47vh |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |