RHSA-2022:6985: Moderate: nodejs:14 security and bug fix update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): nodejs: DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212) nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding (CVE-2022-32213) nodejs: HTTP request smuggling due to improper delimiting of header fields (CVE-2022-32214) nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (CVE-2022-32215) got: missing verification of requested URLs allows redirects to UNIX sockets (CVE-2022-33987) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): nodejs:14/nodejs: rebase to latest upstream release (BZ#2106368) nodejs:14/nodejs: Specify --with-default-icu-data-dir when using bootstrap build (BZ#2111419)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejs-nodemonto a version that resolves this vulnerability.Fixed in 2.0.19-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejs-packagingto a version that resolves this vulnerability.Fixed in 23-3.module+el8.3.0+6519+9f98ed83 - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejs-docsto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 6.14.17-1.14.20.0.2.module+el8.4.0+16234+70f4adc8 - Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8.aa - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8.aa - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8.aa - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8.aa - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 14.20.0-2.module+el8.4.0+16234+70f4adc8.aa - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 6.14.17-1.14.20.0.2.module+el8.4.0+16234+70f4adc8.aa - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Patch CVE-2022-32212 - Upgrade
Upgrade
gotto a version that resolves this vulnerability.Patch CVE-2022-33987 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Patch CVE-2022-32213 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Patch CVE-2022-32214 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Patch CVE-2022-32215 - Upgrade
Upgrade
nodejs:14to a version that resolves this vulnerability.Patch BZ#2111419 - Upgrade
Upgrade
nodejs:14to a version that resolves this vulnerability.Patch BZ#2106368
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2022:6985?
RHSA-2022:6985 addresses a DNS rebinding vulnerability in the Node.js inspect feature and an HTTP request smuggling issue.
What is the severity of RHSA-2022:6985?
The severity of RHSA-2022:6985 is classified as moderate.
How do I fix RHSA-2022:6985?
To fix RHSA-2022:6985, you should update Node.js and its related packages to the specified versions mentioned in the advisory.
Which versions of Node.js are affected by RHSA-2022:6985?
Versions of Node.js earlier than 14.20.0-2.module+el8.4.0+16234+70f4adc8 are affected by RHSA-2022:6985.
Is there a recommended version to upgrade to for RHSA-2022:6985?
The recommended version to upgrade to for addressing RHSA-2022:6985 is 14.20.0-2.module+el8.4.0+16234+70f4adc8.