RHSA-2023:4330: Moderate: nodejs:18 security, bug fix, and enhancement update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The package has been upgraded to a later upstream version: nodejs (18). (BZ#2223314, BZ#2223316, BZ#2223318, BZ#2223319, BZ#2223320, BZ#2223354)Security Fix(es): nodejs: mainModule.proto bypass experimental policy mechanism (CVE-2023-30581) nodejs: process interuption due to invalid Public Key information in x509 certificates (CVE-2023-30588) nodejs: HTTP Request Smuggling via Empty headers separated by CR (CVE-2023-30589) nodejs: DiffieHellman do not generate keys after setting a private key (CVE-2023-30590) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4330?
The severity of RHSA-2023:4330 is classified based on the vulnerabilities it addresses, typically indicating a moderate to high risk.
How do I fix RHSA-2023:4330?
To fix RHSA-2023:4330, update all affected Node.js packages to the specified versions listed in the advisory.
Which Node.js packages are affected by RHSA-2023:4330?
Affected packages in RHSA-2023:4330 include nodejs, nodejs-nodemon, nodejs-docs, and others.
What versions of nodejs are recommended to address RHSA-2023:4330?
It is recommended to upgrade to nodejs version 18.16.1-1.module+el9.2.0 to mitigate the vulnerability.
Can RHSA-2023:4330 affect my application?
Yes, failing to address RHSA-2023:4330 can expose your application to security vulnerabilities that may be exploited.