Security update for nodejs12
This update for nodejs12 fixes the following issues: Update to 12.22.5: - CVE-2021-3672/CVE-2021-22931: Improper handling of untypical characters in domain names (bsc#1189370, bsc#1188881) - CVE-2021-22940: Use after free on close http2 on stream canceling (bsc#1189368) - CVE-2021-22939: Incomplete validation of rejectUnauthorized parameter (bsc#1189369) - CVE-2021-22930: http2: fixes use after free on close http2 on stream canceling (bsc#1188917) This update was imported from the SUSE:SLE-15-SP2:Update update project.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs12 fixes the following issues: Update to 12.22.5: - CVE-2021-3672/CVE-2021-22931: Improper handling of untypical characters in domain names (bsc#1189370, bsc#1188881) - CVE-2021-22940: Use after free on close http2 on stream canceling (bsc#1189368) - CVE-2021-22939: Incomplete validation of rejectUnauthorized parameter (bsc#1189369) - CVE-2021-22930: http2: fixes use after free on close http2 on stream canceling (bsc#1188917) This update was imported from the SUSE:SLE-15-SP2:Update update project.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1188881
- https://bugzilla.suse.com/1188917
- https://bugzilla.suse.com/1189368
- https://bugzilla.suse.com/1189369
- https://bugzilla.suse.com/1189370
- https://lists.opensuse.org/archives/list/[email protected]/thread/ZFSPBU6QGGED7SJWK464GN672ZJB6SMI/
- https://www.suse.com/security/cve/CVE-2021-22930
- https://www.suse.com/security/cve/CVE-2021-22931
- https://www.suse.com/security/cve/CVE-2021-22939
- https://www.suse.com/security/cve/CVE-2021-22940
- https://www.suse.com/security/cve/CVE-2021-3672