[openSUSE-SU-2021:1113-1] Security update for nodejs8

Severity Important
Affected Packages 7
CVEs 3

Security update for nodejs8

This update for nodejs8 fixes the following issues:

  • update to npm 6.14.13
  • CVE-2021-27290: Fixed ssri Regular Expression Denial of Service. (bsc#1187976)
  • CVE-2021-23362: Fixed hosted-git-info Regular Expression Denial of Service. (bsc#1187977)
  • CVE-2020-7774: fixes y18n Prototype Pollution. (bsc#1184450)

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/npm8?arch=x86_64&distro=opensuse-leap-15.2 opensuse npm8 < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/npm8?arch=i586&distro=opensuse-leap-15.2 opensuse npm8 < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 i586
Affected pkg:rpm/opensuse/nodejs8?arch=x86_64&distro=opensuse-leap-15.2 opensuse nodejs8 < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/nodejs8?arch=i586&distro=opensuse-leap-15.2 opensuse nodejs8 < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 i586
Affected pkg:rpm/opensuse/nodejs8-docs?arch=noarch&distro=opensuse-leap-15.2 opensuse nodejs8-docs < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 noarch
Affected pkg:rpm/opensuse/nodejs8-devel?arch=x86_64&distro=opensuse-leap-15.2 opensuse nodejs8-devel < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 x86_64
Affected pkg:rpm/opensuse/nodejs8-devel?arch=i586&distro=opensuse-leap-15.2 opensuse nodejs8-devel < 8.17.0-lp152.3.14.1 opensuse-leap-15.2 i586
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...