RHSA-2020:2848: Important: nodejs:10 security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: nodejs (10.21.0).Security Fix(es): nghttp2: overly large SETTINGS frames can lead to DoS (CVE-2020-11080) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload (CVE-2020-7598) nodejs: memory corruption in napi_get_value_string_* functions (CVE-2020-8174) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2848?
The severity of RHSA-2020:2848 is categorized as moderate.
How do I fix RHSA-2020:2848?
To fix RHSA-2020:2848, upgrade Node.js and related packages to the patched versions provided in the advisory.
Which versions are affected by RHSA-2020:2848?
RHSA-2020:2848 affects Node.js versions prior to 10.21.0-3.module+el8.2.0+7071+d2377ea3.
What packages are included in the RHSA-2020:2848 advisory?
The RHSA-2020:2848 advisory includes updates for nodejs, nodejs-nodemon, npm, and other nodejs-related packages.
Is there a specific fix version for nodejs in RHSA-2020:2848?
Yes, the specific fix version for nodejs in RHSA-2020:2848 is 10.21.0-3.module+el8.2.0+7071+d2377ea3.