[ELSA-2024-1444] nodejs:16 security update

Severity Important
Affected Packages 7
CVEs 2

nodejs
[1:16.20.2-4.0.1]
- reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks
Resolves: CVE-2024-22019

nodejs-nodemon
nodejs-packaging
[26-1]
- nodejs.prov: find namespaced bundled dependencies
- Apply https://src.fedoraproject.org/rpms/nodejs-packaging/c/e24e7df

Package Affected Version
pkg:rpm/oraclelinux/npm?distro=oraclelinux-8.9 < 8.19.4-1.16.20.2.4.0.1.module+el8.9.0+90185+b2d3b544
pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-8.9 < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544
pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-8.9 < 26-1.module+el8.9.0+90185+b2d3b544
pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-8.9 < 3.0.1-1.module+el8.9.0+90185+b2d3b544
pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-8.9 < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544
pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-8.9 < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544
pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-8.9 < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544
ID
ELSA-2024-1444
Severity
important
URL
https://linux.oracle.com/errata/ELSA-2024-1444.html
Published
2024-03-21T00:00:00
(6 months ago)
Modified
2024-03-21T00:00:00
(6 months ago)
Rights
Copyright 2024 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/npm?distro=oraclelinux-8.9 oraclelinux npm < 8.19.4-1.16.20.2.4.0.1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs?distro=oraclelinux-8.9 oraclelinux nodejs < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-packaging?distro=oraclelinux-8.9 oraclelinux nodejs-packaging < 26-1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-nodemon?distro=oraclelinux-8.9 oraclelinux nodejs-nodemon < 3.0.1-1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-full-i18n?distro=oraclelinux-8.9 oraclelinux nodejs-full-i18n < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-docs?distro=oraclelinux-8.9 oraclelinux nodejs-docs < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
Affected pkg:rpm/oraclelinux/nodejs-devel?distro=oraclelinux-8.9 oraclelinux nodejs-devel < 16.20.2-4.0.1.module+el8.9.0+90185+b2d3b544 oraclelinux-8.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...