RHSA-2021:2932: Moderate: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.17.2).Security Fix(es): nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl() (CVE-2021-23362) nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode (CVE-2021-27290) normalize-url: ReDoS for data URLs (CVE-2021-33502) libuv: out-of-bounds read in uvidnatoascii() can lead to information disclosures or crashes (CVE-2021-22918) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): ECDHE ciphers missing in rh-nodejs14 (BZ#1942591)
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the security fixes included in RHSA-2021:2932?
RHSA-2021:2932 includes security fixes for vulnerabilities reported against the Node.js packages.
What is the recommended version to upgrade to for RHSA-2021:2932?
The recommended version to upgrade to for RHSA-2021:2932 is rh-nodejs14-nodejs 14.17.2-1.el7.
How do I resolve the vulnerabilities identified in RHSA-2021:2932?
To resolve the vulnerabilities in RHSA-2021:2932, update all affected packages, including rh-nodejs14-nodejs, rh-nodejs14-nodemon, and rh-nodejs14-npm.
Which packages are affected by RHSA-2021:2932?
The packages affected by RHSA-2021:2932 include rh-nodejs14-nodejs, rh-nodejs14-nodejs-nodemon, and rh-nodejs14-npm.
What platforms does RHSA-2021:2932 affect?
RHSA-2021:2932 affects the Red Hat Enterprise Linux 7 platform.