[FREEBSD:C0C1834C-9761-11EB-ACFD-0022489AD614] Node.js -- April 2021 Security Releases

Severity Critical
Affected Packages 4
CVEs 3

Node.js reports:

  OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High) (CVE-2021-3450)
  This is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20210325.txt
  OpenSSL - NULL pointer deref in signature_algorithms processing (High) (CVE-2021-3449)
  This is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20210325.txt
  npm upgrade - Update y18n to fix Prototype-Pollution (High) (CVE-2020-7774)
  This is a vulnerability in the y18n npm module which may be exploited by prototype pollution. You can read more about it in https://github.com/advisories/GHSA-c4w7-xm78-47vh
Package Affected Version
pkg:freebsd/node14 < 14.16.1
pkg:freebsd/node12 < 12.22.1
pkg:freebsd/node10 < 10.24.1
pkg:freebsd/node < 15.14.0
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/node14 node14 < 14.16.1
Affected pkg:freebsd/node12 node12 < 12.22.1
Affected pkg:freebsd/node10 node10 < 10.24.1
Affected pkg:freebsd/node node < 15.14.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...