RHSA-2024:1880HighCVSS 8.1
Red Hat Security Advisory: nodejs:18 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-46809 — nodejs: vulnerable to timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding (Marvin) CVE-2024-21892 — nodejs: code injection and privilege escalation through Linux capabilities CVE-2024-22019 — nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:1880
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264569
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264574
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264582
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1880.json