RHSA-2022:0246MediumCVSS 9.8

Red Hat Security Advisory: nodejs:14 security, bug fix, and enhancement update

Published
January 25, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2020-7788 — nodejs-ini: Prototype pollution via malicious INI file CVE-2020-28469 — nodejs-glob-parent: Regular expression denial of service CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2021-3918 — nodejs-json-schema: Prototype pollution vulnerability CVE-2021-22959 — llhttp: HTTP Request Smuggling due to spaces in headers CVE-2021-22960 — llhttp: HTTP Request Smuggling when parsing the body of chunked requests CVE-2021-33502 — nodejs-normalize-url: ReDoS for data URLs CVE-2021-37701 — nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite CVE-2021-37712 — nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite

🎯 Affected products31

  • Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.aarch64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.ppc64le (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.s390x (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.src (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.x86_64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debuginfo-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.aarch64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debuginfo-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.ppc64le (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debuginfo-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.s390x (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debuginfo-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.x86_64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debugsource-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.aarch64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debugsource-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.ppc64le (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debugsource-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.s390x (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-debugsource-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.x86_64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-devel-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.aarch64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-devel-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.ppc64le (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-devel-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.s390x (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-devel-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.x86_64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-docs-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.noarch (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-full-i18n-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.aarch64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-full-i18n-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.ppc64le (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-full-i18n-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.s390x (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-full-i18n-1:14.18.2-2.module+el8.4.0+13643+6c0ebf22.x86_64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-nodemon-0:2.0.15-1.module+el8.4.0+13503+fc29810b.noarch (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-nodemon-0:2.0.15-1.module+el8.4.0+13503+fc29810b.src (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-packaging-0:23-3.module+el8.3.0+6519+9f98ed83.noarch (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • nodejs-packaging-0:23-3.module+el8.3.0+6519+9f98ed83.src (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • npm-1:6.14.15-1.14.18.2.2.module+el8.4.0+13643+6c0ebf22.aarch64 (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • npm-1:6.14.15-1.14.18.2.2.module+el8.4.0+13643+6c0ebf22.ppc64le (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • npm-1:6.14.15-1.14.18.2.2.module+el8.4.0+13643+6c0ebf22.s390x (nodejs:14) as a component of Red Hat Enterprise Linux AppStream EUS (v.8.4)
  • +1 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (12)