Red Hat Security Advisory: rh-nodejs12-nodejs security, bug fix, and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2021-3918 — nodejs-json-schema: Prototype pollution vulnerability CVE-2021-22959 — llhttp: HTTP Request Smuggling due to spaces in headers CVE-2021-22960 — llhttp: HTTP Request Smuggling when parsing the body of chunked requests CVE-2021-37701 — nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite CVE-2021-37712 — nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite CVE-2021-44531 — nodejs: Improper handling of URI Subject Alternative Names CVE-2021-44532 — nodejs: Certificate Verification Bypass via String Injection CVE-2021-44533 — nodejs: Incorrect handling of certificate subject and issuer fields CVE-2021-44906 — minimist: prototype pollution CVE-2022-21824 — nodejs: Prototype pollution via console.table properties
🎯 Affected products22
- Red Hat Software Collections for RHEL Workstation(v. 7)
- Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs12-nodejs-0:12.22.12-2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-0:12.22.12-2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-0:12.22.12-2.el7.src as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-0:12.22.12-2.el7.src as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs12-nodejs-0:12.22.12-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-0:12.22.12-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs12-nodejs-debuginfo-0:12.22.12-2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-debuginfo-0:12.22.12-2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-debuginfo-0:12.22.12-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-debuginfo-0:12.22.12-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs12-nodejs-devel-0:12.22.12-2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-devel-0:12.22.12-2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-devel-0:12.22.12-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-devel-0:12.22.12-2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs12-nodejs-docs-0:12.22.12-2.el7.noarch as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-nodejs-docs-0:12.22.12-2.el7.noarch as a component of Red Hat Software Collections for RHEL(v. 7)
- rh-nodejs12-npm-0:6.14.16-12.22.12.2.el7.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-npm-0:6.14.16-12.22.12.2.el7.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-npm-0:6.14.16-12.22.12.2.el7.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- rh-nodejs12-npm-0:6.14.16-12.22.12.2.el7.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2022:4914
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999731
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014059
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040846
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066009
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_4914.json