[ELSA-2023-2654] nodejs:18 security, bug fix, and enhancement update

Severity Moderate
Affected Packages 8
CVEs 8

nodejs
[1:18.14.2-2]
- Provide simduft
- Resolves: #2159389

[1:18.14.2-1]
- Rebase to 18.14.2
- Resolves: #2159389
- Resolves: CVE-2022-25881, CVE-2022-4904, CVE-2023-23936, CVE-2023-24807
- Resolves: CVE-2023-23918, CVE-2023-23919, CVE-2023-23920

nodejs-nodemon
[2.0.20-2]
- Patch bundled glob-parent
- Resolves: CVE-2021-35065

nodejs-packaging

Package Affected Version
pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 < 9.5.0-1.18.14.2.2.module+el9.2.0+21038+115df6a2
pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 < 18.14.2-2.module+el9.2.0+21038+115df6a2
pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-9.1 < 2021.06-4.module+el9.1.0+20762+f52d7401
pkg:rpm/oraclelinux/nodejs-packaging-bundler?distro=oraclelinux-9.1 < 2021.06-4.module+el9.1.0+20762+f52d7401
pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-9.2 < 2.0.20-2.module+el9.2.0+21038+115df6a2
pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 < 18.14.2-2.module+el9.2.0+21038+115df6a2
pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 < 18.14.2-2.module+el9.2.0+21038+115df6a2
pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-9.2 < 18.14.2-2.module+el9.2.0+21038+115df6a2
ID
ELSA-2023-2654
Severity
moderate
URL
https://linux.oracle.com/errata/ELSA-2023-2654.html
Published
2023-05-17T00:00:00
(16 months ago)
Modified
2023-05-17T00:00:00
(16 months ago)
Rights
Copyright 2023 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 oraclelinux npm < 9.5.0-1.18.14.2.2.module+el9.2.0+21038+115df6a2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 oraclelinux nodejs < 18.14.2-2.module+el9.2.0+21038+115df6a2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-9.1 oraclelinux nodejs-packaging < 2021.06-4.module+el9.1.0+20762+f52d7401 oraclelinux-9.1
Affected pkg:rpm/oraclelinux/nodejs-packaging-bundler?distro=oraclelinux-9.1 oraclelinux nodejs-packaging-bundler < 2021.06-4.module+el9.1.0+20762+f52d7401 oraclelinux-9.1
Affected pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-9.2 oraclelinux nodejs-nodemon < 2.0.20-2.module+el9.2.0+21038+115df6a2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 oraclelinux nodejs-full-i18n < 18.14.2-2.module+el9.2.0+21038+115df6a2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 oraclelinux nodejs-docs < 18.14.2-2.module+el9.2.0+21038+115df6a2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-9.2 oraclelinux nodejs-devel < 18.14.2-2.module+el9.2.0+21038+115df6a2 oraclelinux-9.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...