A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations. References: https://nodejs.org/en/blog/vulnerability/october-2023-security-releases
Created nodejs tracking bugs for this issue: Affects: epel-7 [bug 2244441] Affects: fedora-37 [bug 2244447] Created nodejs16 tracking bugs for this issue: Affects: fedora-38 [bug 2244442] Created nodejs18 tracking bugs for this issue: Affects: fedora-38 [bug 2244443] Created nodejs20 tracking bugs for this issue: Affects: fedora-38 [bug 2244444] Created nodejs:13/nodejs tracking bugs for this issue: Affects: epel-8 [bug 2244450] Created nodejs:14/nodejs tracking bugs for this issue: Affects: fedora-37 [bug 2244448] Created nodejs:16-epel/nodejs tracking bugs for this issue: Affects: epel-8 [bug 2244449] Created nodejs:16/nodejs tracking bugs for this issue: Affects: fedora-38 [bug 2244445] Created nodejs:18/nodejs tracking bugs for this issue: Affects: fedora-37 [bug 2244446]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7205 https://access.redhat.com/errata/RHSA-2023:7205
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHEA-2023:6529 https://access.redhat.com/errata/RHEA-2023:6529
Created nodejs tracking bugs for this issue: Affects: epel-7 [bug 2258562] Created nodejs20 tracking bugs for this issue: Affects: fedora-38 [bug 2258563]
This comment was flagged a spam, view the edit history to see the original text if required.