RHSA-2022:6389MediumCVSS 7.5
Red Hat Security Advisory: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-32212 — nodejs: DNS rebinding in --inspect via invalid IP addresses CVE-2022-32213 — nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding CVE-2022-32214 — nodejs: HTTP request smuggling due to improper delimiting of header fields CVE-2022-32215 — nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding CVE-2022-33987 — nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets
🎯 Affected products26
- Red Hat Software Collections for RHEL Workstation(v. 7)
- Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-0:14.20.0-2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-0:14.20.0-2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-0:14.20.0-2.el7.src as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-0:14.20.0-2.el7.src as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-0:14.20.0-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-0:14.20.0-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-debuginfo-0:14.20.0-2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-debuginfo-0:14.20.0-2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-debuginfo-0:14.20.0-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-debuginfo-0:14.20.0-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-devel-0:14.20.0-2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-devel-0:14.20.0-2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-devel-0:14.20.0-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-devel-0:14.20.0-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-docs-0:14.20.0-2.el7.noarch as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-docs-0:14.20.0-2.el7.noarch as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-nodemon-0:2.0.19-1.el7.noarch as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-nodemon-0:2.0.19-1.el7.noarch as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-nodejs-nodemon-0:2.0.19-1.el7.src as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-nodejs-nodemon-0:2.0.19-1.el7.src as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs14-npm-0:6.14.17-14.20.0.2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-npm-0:6.14.17-14.20.0.2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-npm-0:6.14.17-14.20.0.2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs14-npm-0:6.14.17-14.20.0.2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2022:6389
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2102001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105430
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2106673
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6389.json