[ELSA-2023-7205] nodejs:20 security update

Severity Important
Affected Packages 8
CVEs 6

nodejs
[1:20.8.1-1]
- Update node and nghttp
- Add fips patch
- Fixes CVE-2023-44487 (nghttp)
- Fixes CVE-2023-45143, CVE-2023-39331, CVE-2023-39332, CVE-2023-38552, CVE-2023-39333

nodejs-nodemon
nodejs-packaging

Package Affected Version
pkg:rpm/oraclelinux/npm?distro=oraclelinux-8.9 < 10.1.0-1.20.8.1.1.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-8.9 < 20.8.1-1.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-8.9 < 2021.06-4.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs-packaging-bundler?distro=oraclelinux-8.9 < 2021.06-4.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-8.9 < 3.0.1-1.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-8.9 < 20.8.1-1.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-8.9 < 20.8.1-1.module+el8.9.0+90082+b6a613a6
pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-8.9 < 20.8.1-1.module+el8.9.0+90082+b6a613a6
ID
ELSA-2023-7205
Severity
important
URL
https://linux.oracle.com/errata/ELSA-2023-7205.html
Published
2023-11-22T00:00:00
(9 months ago)
Modified
2023-11-22T00:00:00
(9 months ago)
Rights
Copyright 2023 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/npm?distro=oraclelinux-8.9 oraclelinux npm < 10.1.0-1.20.8.1.1.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-8.9 oraclelinux nodejs < 20.8.1-1.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-8.9 oraclelinux nodejs-packaging < 2021.06-4.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-packaging-bundler?distro=oraclelinux-8.9 oraclelinux nodejs-packaging-bundler < 2021.06-4.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-8.9 oraclelinux nodejs-nodemon < 3.0.1-1.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-8.9 oraclelinux nodejs-full-i18n < 20.8.1-1.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-8.9 oraclelinux nodejs-docs < 20.8.1-1.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-8.9 oraclelinux nodejs-devel < 20.8.1-1.module+el8.9.0+90082+b6a613a6 oraclelinux-8.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...