Red Hat Security Advisory: nodejs and nodejs-nodemon security and bug fix update
🔗 CVE IDs covered (10)
📋 Description
CVE-2020-7788 — nodejs-ini: Prototype pollution via malicious INI file CVE-2020-28469 — nodejs-glob-parent: Regular expression denial of service CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2021-33502 — nodejs-normalize-url: ReDoS for data URLs CVE-2022-29244 — nodejs: npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace CVE-2022-32212 — nodejs: DNS rebinding in --inspect via invalid IP addresses CVE-2022-32213 — nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding CVE-2022-32214 — nodejs: HTTP request smuggling due to improper delimiting of header fields CVE-2022-32215 — nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding CVE-2022-33987 — nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets
🎯 Affected products37
- Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-1:16.16.0-1.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-1:16.16.0-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-1:16.16.0-1.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-1:16.16.0-1.el9_0.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-1:16.16.0-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debuginfo-1:16.16.0-1.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debuginfo-1:16.16.0-1.el9_0.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debuginfo-1:16.16.0-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debuginfo-1:16.16.0-1.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debuginfo-1:16.16.0-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debugsource-1:16.16.0-1.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debugsource-1:16.16.0-1.el9_0.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debugsource-1:16.16.0-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debugsource-1:16.16.0-1.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-debugsource-1:16.16.0-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-docs-1:16.16.0-1.el9_0.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-full-i18n-1:16.16.0-1.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-full-i18n-1:16.16.0-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-full-i18n-1:16.16.0-1.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-full-i18n-1:16.16.0-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-1:16.16.0-1.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-1:16.16.0-1.el9_0.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-1:16.16.0-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-1:16.16.0-1.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-1:16.16.0-1.el9_0.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-debuginfo-1:16.16.0-1.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-debuginfo-1:16.16.0-1.el9_0.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-debuginfo-1:16.16.0-1.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- nodejs-libs-debuginfo-1:16.16.0-1.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- +7 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2022:6595
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1907444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1945459
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1964461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2098556
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2102001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105430
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2121019
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124299
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6595.json