RHSA-2020:2625: Moderate: rh-nodejs8-nodejs security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.The following packages have been upgraded to a later upstream version: rh-nodejs8-nodejs (8.17.0). (BZ#1829414)Security Fix(es): nodejs-brace-expansion: Regular expression denial of service (CVE-2017-18077) nodejs-chownr: TOCTOU vulnerability in chownr function in chownr.js (CVE-2017-18869) nodejs-sshpk: ReDoS when parsing crafted invalid public keys in lib/formats/ssh.js (CVE-2018-3737) nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties (CVE-2018-3750) npm: Symlink reference outside of nodemodules folder through the bin field upon installation (CVE-2019-16775) npm: Arbitrary file write via constructed entry in the package.json bin field (CVE-2019-16776) npm: Global nodemodules Binary Overwrite (CVE-2019-16777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-nodejs8-nodejsto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-nodejs-develto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-nodejs-docsto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-npmto a version that resolves this vulnerability.Fixed in 6.13.4-8.17.0.2.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-nodejsto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7.aa - Upgrade
Upgrade
redhat/rh-nodejs8-nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7.aa - Upgrade
Upgrade
redhat/rh-nodejs8-nodejs-develto a version that resolves this vulnerability.Fixed in 8.17.0-2.el7.aa - Upgrade
Upgrade
redhat/rh-nodejs8-npmto a version that resolves this vulnerability.Fixed in 6.13.4-8.17.0.2.el7.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2625?
The severity of RHSA-2020:2625 is classified as important.
How do I fix RHSA-2020:2625?
To fix RHSA-2020:2625, upgrade to the packages rh-nodejs8-nodejs version 8.17.0-2.el7 or later.
What are the affected packages in RHSA-2020:2625?
The affected packages in RHSA-2020:2625 include rh-nodejs8-nodejs, rh-nodejs8-npm, rh-nodejs8-nodejs-devel, and rh-nodejs8-nodejs-docs.
When was RHSA-2020:2625 released?
RHSA-2020:2625 was released on June 24, 2020.
What vulnerabilities does RHSA-2020:2625 address?
RHSA-2020:2625 addresses multiple security vulnerabilities related to node.js.