Mageia 2022-0422: nodejs security update
Summary
DNS rebinding in --inspect via invalid octal IP address (CVE-2022-43548)
In addition, 14.21.0 has provided the following changes:
deps
update corepack to 0.14.2 (Node.js GitHub Bot) #44775
src
add --openssl-shared-config option (Daniel Bevenius) #43124
References
- https://bugs.mageia.org/show_bug.cgi?id=31078
- https://github.com/nodejs/node/releases/tag/v14.21.1
- https://github.com/nodejs/node/releases/tag/v14.21.0
- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/
- https://nodejs.org/en/blog/release/v18.12.1/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43548
Resolution
MGASA-2022-0422 - Updated nodejs packages fix security vulnerability
SRPMS
- 8/core/nodejs-14.21.1-1.1.mga8