[RLSA-2021:3073] nodejs:12 security, bug fix, and enhancement update
An update is available for nodejs-nodemon, nodejs, nodejs-packaging. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
The following packages have been upgraded to a later upstream version: nodejs (12.22.3). (BZ#1978201)
Security Fix(es):
nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl() (CVE-2021-23362)
nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode (CVE-2021-27290)
libuv: out-of-bounds read in uv__idna_toascii() can lead to information disclosures or crashes (CVE-2021-22918)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
- ID
- RLSA-2021:3073
- Severity
- moderate
- URL
- https://errata.rockylinux.org/RLSA-2021:3073
- Published
-
2021-08-10T12:00:47
(3 years ago) - Modified
-
2023-02-02T13:26:48
(19 months ago) - Rights
- Copyright 2024 Rocky Enterprise Software Foundation
- Other Advisories
-
- ALAS2-2024-2410
- ALPINE:CVE-2021-22918
- ALPINE:CVE-2021-27290
- ALSA-2021:3073
- ALSA-2021:3074
- ALSA-2021:3075
- ASA-202107-13
- ASA-202107-36
- DSA-4936-1
- ELSA-2021-3073
- ELSA-2021-3074
- ELSA-2021-3075
- FREEBSD:C174118E-1B11-11EC-9D9D-0022489AD614
- GLSA-202401-23
- GLSA-202405-29
- MS:CVE-2021-22918
- NPM:GHSA-43F8-2H32-F4CJ
- NPM:GHSA-VX3P-948G-6VHQ
- openSUSE-SU-2021:1059-1
- openSUSE-SU-2021:1060-1
- openSUSE-SU-2021:1061-1
- openSUSE-SU-2021:1113-1
- openSUSE-SU-2021:2327-1
- openSUSE-SU-2021:2353-1
- openSUSE-SU-2021:2354-1
- openSUSE-SU-2021:2618-1
- RHSA-2021:3073
- RHSA-2021:3074
- RHSA-2021:3075
- RLSA-2021:3074
- RLSA-2021:3075
- SUSE-SU-2021:2319-1
- SUSE-SU-2021:2323-1
- SUSE-SU-2021:2326-1
- SUSE-SU-2021:2327-1
- SUSE-SU-2021:2353-1
- SUSE-SU-2021:2354-1
- SUSE-SU-2021:2618-1
- SUSE-SU-2021:2620-1
- USN-5007-1
- USN-5216-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2021-22918 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22918 | |
CVE | CVE-2021-23362 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23362 | |
CVE | CVE-2021-27290 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27290 | |
Bugzilla | 1941471 | https://bugzilla.redhat.com/show_bug.cgi?id=1941471 | |
Bugzilla | 1943208 | https://bugzilla.redhat.com/show_bug.cgi?id=1943208 | |
Bugzilla | 1979338 | https://bugzilla.redhat.com/show_bug.cgi?id=1979338 | |
Self | RLSA-2021:3073 | https://errata.rockylinux.org/RLSA-2021:3073 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/rockylinux/npm?arch=x86_64&distro=rockylinux-8.4 | rockylinux | npm | < 6.14.13-1.14.17.3.2.module+el8.4.0+639+18660d0d | rockylinux-8.4 | x86_64 | |
Affected | pkg:rpm/rockylinux/npm?arch=aarch64&distro=rockylinux-8.4 | rockylinux | npm | < 6.14.13-1.14.17.3.2.module+el8.4.0+639+18660d0d | rockylinux-8.4 | aarch64 | |
Affected | pkg:rpm/rockylinux/nodejs?arch=x86_64&distro=rockylinux-8.4 | rockylinux | nodejs | < 12.22.3-2.module+el8.4.0+638+5344c6f7 | rockylinux-8.4 | x86_64 | |
Affected | pkg:rpm/rockylinux/nodejs?arch=aarch64&distro=rockylinux-8.4 | rockylinux | nodejs | < 14.17.3-2.module+el8.4.0+639+18660d0d | rockylinux-8.4 | aarch64 | |
Affected | pkg:rpm/rockylinux/nodejs-packaging?arch=noarch&distro=rockylinux-8.3 | rockylinux | nodejs-packaging | < 17-3.module+el8.3.0+101+f84c7154 | rockylinux-8.3 | noarch | |
Affected | pkg:rpm/rockylinux/nodejs-nodemon?arch=noarch&distro=rockylinux-8.6 | rockylinux | nodejs-nodemon | < 2.0.3-1.module+el8.6.0+982+9fdca2d4 | rockylinux-8.6 | noarch | |
Affected | pkg:rpm/rockylinux/nodejs-nodemon?arch=noarch&distro=rockylinux-8.4 | rockylinux | nodejs-nodemon | < 2.0.3-1.module+el8.4.0+638+5344c6f7 | rockylinux-8.4 | noarch | |
Affected | pkg:rpm/rockylinux/nodejs-full-i18n?arch=x86_64&distro=rockylinux-8.4 | rockylinux | nodejs-full-i18n | < 14.17.3-2.module+el8.4.0+639+18660d0d | rockylinux-8.4 | x86_64 | |
Affected | pkg:rpm/rockylinux/nodejs-full-i18n?arch=aarch64&distro=rockylinux-8.4 | rockylinux | nodejs-full-i18n | < 12.22.3-2.module+el8.4.0+638+5344c6f7 | rockylinux-8.4 | aarch64 | |
Affected | pkg:rpm/rockylinux/nodejs-docs?arch=noarch&distro=rockylinux-8.4 | rockylinux | nodejs-docs | < 14.17.3-2.module+el8.4.0+639+18660d0d | rockylinux-8.4 | noarch | |
Affected | pkg:rpm/rockylinux/nodejs-devel?arch=x86_64&distro=rockylinux-8.4 | rockylinux | nodejs-devel | < 12.22.3-2.module+el8.4.0+638+5344c6f7 | rockylinux-8.4 | x86_64 | |
Affected | pkg:rpm/rockylinux/nodejs-devel?arch=aarch64&distro=rockylinux-8.4 | rockylinux | nodejs-devel | < 12.22.3-2.module+el8.4.0+638+5344c6f7 | rockylinux-8.4 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |