RHSA-2023:5362: Important: nodejs:18 security, bug fix, and enhancement update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: nodejs (18). (BZ#2234409)Security Fix(es): nodejs: Permissions policies can be bypassed via Module._load (CVE-2023-32002) nodejs-semver: Regular expression denial of service (CVE-2022-25883) nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006) nodejs: Permissions policies can be bypassed via process.binding (CVE-2023-32559) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the key security fixes in RHSA-2023:5362?
The key security fix addresses permission vulnerabilities in Node.js.
How can I resolve the vulnerability identified in RHSA-2023:5362?
To resolve the vulnerability in RHSA-2023:5362, upgrade to nodejs version 18.17.1-1.module+el8.8.0+19757+8ca87034.
Which packages are affected by RHSA-2023:5362?
RHSA-2023:5362 impacts packages related to nodejs, including nodejs-nodemon, nodejs-packaging, and npm.
What is the severity level of the vulnerability in RHSA-2023:5362?
The vulnerability in RHSA-2023:5362 is categorized as a moderate severity issue.
Is it safe to use Node.js versions prior to the fix in RHSA-2023:5362?
Using Node.js versions prior to the fix in RHSA-2023:5362 is not recommended due to security risks.