RHSA-2024:1354: Important: rh-nodejs14 security update
Important: rh-nodejs14 security update
Other sources
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. <br>Security Fix(es):<br><li> rh-nodejs14-nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (CVE-2024-22019)</li> A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section.<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1354?
The severity of RHSA-2024:1354 is classified as important.
How do I fix RHSA-2024:1354?
To fix RHSA-2024:1354, update the affected rh-nodejs14-nodejs package to version 14.21.3-6.el7.
What are the affected packages in RHSA-2024:1354?
The affected packages in RHSA-2024:1354 include rh-nodejs14-nodejs, rh-nodejs14-nodejs-devel, and rh-nodejs14-npm among others.
What is the key vulnerability addressed in RHSA-2024:1354?
RHSA-2024:1354 addresses a vulnerability related to reading unprocessed HTTP requests with unbounded chunk extensions.
Is RHSA-2024:1354 applicable to all versions of Node.js?
RHSA-2024:1354 specifically affects rh-nodejs14 and does not apply to all versions of Node.js.