[ELSA-2023-3586] nodejs security update

Severity Important
Affected Packages 5
CVEs 4

[1:16.19.1-2]
- Update bundled c-ares to 1.19.1
Resolves: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067

[1:16.19.1-1]
- Rebase to 16.19.1
- Resolves: rhbz#2153714
- Resolves: CVE-2023-23918 CVE-2023-23919 CVE-2023-23936 CVE-2023-24807 CVE-2023-23920
- Resolves: CVE-2022-25881 CVE-2022-4904

[1:16.18.1-3]
- Update sources of undici WASM blobs
Resolves: rhbz#2151617

[1:16.18.1-2]
- Add back libs and v8-devel subpackages
- Related: RHBZ#2121126
- Record previously fixed CVE
- Resolves: CVE-2021-44906

[1:16.18.1-1]
- Rebase + CVEs
- Resolves: #2142808
- Resolves: #2142826, #2131745, #2142855

[16.17.1-1]
- Rebase to version 16.17.1
Resolves: CVE-2022-35255 CVE-2022-35256

[16.16.0-1]
- Rebase to version 16.16.0
Resolves: RHBZ#2106290
Resolves: CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215
Resolves: CVE-2022-29244

[16.14.0-5]
- Decouple dependency bundling from bootstrapping

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 oraclelinux npm < 8.19.3-1.16.19.1.2.el9_2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 oraclelinux nodejs < 16.19.1-2.el9_2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-libs?distro=oraclelinux-9.2 oraclelinux nodejs-libs < 16.19.1-2.el9_2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 oraclelinux nodejs-full-i18n < 16.19.1-2.el9_2 oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 oraclelinux nodejs-docs < 16.19.1-2.el9_2 oraclelinux-9.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...