[openSUSE-SU-2021:0356-1] Security update for nodejs14

Severity Important
Affected Packages 4
CVEs 2

Security update for nodejs14

This update for nodejs14 fixes the following issues:

  • New upstream LTS version 14.16.0:
    • CVE-2021-22883: HTTP2 'unknownProtocol' cause Denial of Service by resource exhaustion (bsc#1182619)
    • CVE-2021-22884: DNS rebinding in --inspect (bsc#1182620)

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/npm14?arch=x86_64&distro=opensuse-leap-15.2 opensuse npm14 < 14.16.0-lp152.8.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/nodejs14?arch=x86_64&distro=opensuse-leap-15.2 opensuse nodejs14 < 14.16.0-lp152.8.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/nodejs14-docs?arch=noarch&distro=opensuse-leap-15.2 opensuse nodejs14-docs < 14.16.0-lp152.8.1 opensuse-leap-15.2 noarch
Affected pkg:rpm/opensuse/nodejs14-devel?arch=x86_64&distro=opensuse-leap-15.2 opensuse nodejs14-devel < 14.16.0-lp152.8.1 opensuse-leap-15.2 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...