RHSA-2022:6449: Moderate: nodejs:16 security and bug fix update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807) nodejs: DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212) nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding (CVE-2022-32213) nodejs: HTTP request smuggling due to improper delimiting of header fields (CVE-2022-32214) nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (CVE-2022-32215) got: missing verification of requested URLs allows redirects to UNIX sockets (CVE-2022-33987) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): nodejs:16/nodejs: rebase to latest upstream release (BZ#2106369) nodejs:16/nodejs: Specify --with-default-icu-data-dir when using bootstrap build (BZ#2111416)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6449?
RHSA-2022:6449 is classified as a moderate severity vulnerability.
How do I fix RHSA-2022:6449?
To remediate RHSA-2022:6449, update the affected packages to their fixed versions as specified in the advisory.
What vulnerabilities are addressed in RHSA-2022:6449?
RHSA-2022:6449 addresses a Regular Expression Denial of Service (ReDoS) vulnerability in the nodejs-ansi-regex package (CVE-2021-3807).
Which packages are affected by RHSA-2022:6449?
The affected packages in RHSA-2022:6449 include nodejs, nodejs-nodemon, and nodejs-packaging among others.
When was RHSA-2022:6449 released?
RHSA-2022:6449 was released on December 20, 2022.