[ELSA-2023-5849] 18 security update

Severity Important
Affected Packages 8
CVEs 4

nodejs
[1:18.18.2-2]
- Rebase to version 18.18.2
Resolves: CVE-2023-44487 CVE-2023-45143 CVE-2023-38552 CVE-2023-39333

nodejs-nodemon
[3.0.1-1]
- Rebase to 3.0.1
- Resolves: CVE-2022-25883

nodejs-packaging
[2021.06-4]
- NPM bundler: also find namespaced bundled dependencies

[2021.06-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild

[2021.06-2]
- Fix hard-coded output directory in the bundler

[2021.06-1]
- Update to 2021.06-1
- bundler: Handle archaic license metadata
- bundler: Warn about bundled dependencies with no license metadata

[2021.01-3]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

[2021.01-2]
- nodejs-packaging-bundler improvements to handle uncommon characters

[2021.01]
- Add nodejs-packaging-bundler and update README.md

[2020.09-1]
- Move to dist-git as the upstream

[25-1]
- Fix incorrect bundled library detection for Requires

[24-1]
- Check node_modules_prod for bundled dependencies

[23-4]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

[23-3]
- Drop Requires: nodejs(engine)

[23-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild

Package Affected Version
pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 < 9.8.1-1.18.18.2.2.module+el9.2.0+21194+c0bbf6cf
pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf
pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-9.1 < 2021.06-4.module+el9.1.0+20762+f52d7401
pkg:rpm/oraclelinux/nodejs-packaging-bundler?distro=oraclelinux-9.1 < 2021.06-4.module+el9.1.0+20762+f52d7401
pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-9.2 < 3.0.1-1.module+el9.2.0+21169+1d24b6cc
pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf
pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf
pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-9.2 < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf
ID
ELSA-2023-5849
Severity
important
URL
https://linux.oracle.com/errata/ELSA-2023-5849.html
Published
2023-10-20T00:00:00
(11 months ago)
Modified
2023-10-20T00:00:00
(11 months ago)
Rights
Copyright 2023 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/npm?distro=oraclelinux-9.2 oraclelinux npm < 9.8.1-1.18.18.2.2.module+el9.2.0+21194+c0bbf6cf oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-9.2 oraclelinux nodejs < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-9.1 oraclelinux nodejs-packaging < 2021.06-4.module+el9.1.0+20762+f52d7401 oraclelinux-9.1
Affected pkg:rpm/oraclelinux/nodejs-packaging-bundler?distro=oraclelinux-9.1 oraclelinux nodejs-packaging-bundler < 2021.06-4.module+el9.1.0+20762+f52d7401 oraclelinux-9.1
Affected pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-9.2 oraclelinux nodejs-nodemon < 3.0.1-1.module+el9.2.0+21169+1d24b6cc oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-9.2 oraclelinux nodejs-full-i18n < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-9.2 oraclelinux nodejs-docs < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf oraclelinux-9.2
Affected pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-9.2 oraclelinux nodejs-devel < 18.18.2-2.module+el9.2.0+21194+c0bbf6cf oraclelinux-9.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...