Security update for nodejs14
This update for nodejs14 fixes the following issues: - CVE-2021-3672: Fixed missing input validation on hostnames (bsc#1188881). - CVE-2021-22931: Fixed improper handling of untypical characters in domain names (bsc#1189370). - CVE-2021-22940: Use after free on close http2 on stream canceling (bsc#1189368) - CVE-2021-22939: Incomplete validation of rejectUnauthorized parameter (bsc#1189369) - CVE-2021-22930: Fixed use after free on close http2 on stream canceling (bsc#1188917). This update was imported from the SUSE:SLE-15-SP2:Update update project.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs14 fixes the following issues: - CVE-2021-3672: Fixed missing input validation on hostnames (bsc#1188881). - CVE-2021-22931: Fixed improper handling of untypical characters in domain names (bsc#1189370). - CVE-2021-22940: Use after free on close http2 on stream canceling (bsc#1189368) - CVE-2021-22939: Incomplete validation of rejectUnauthorized parameter (bsc#1189369) - CVE-2021-22930: Fixed use after free on close http2 on stream canceling (bsc#1188917). This update was imported from the SUSE:SLE-15-SP2:Update update project.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1188881
- https://bugzilla.suse.com/1188917
- https://bugzilla.suse.com/1189368
- https://bugzilla.suse.com/1189369
- https://bugzilla.suse.com/1189370
- https://lists.opensuse.org/archives/list/[email protected]/thread/HT3PAHM4M6Q56XJOJVVIZBROY2Y4SUU2/
- https://www.suse.com/security/cve/CVE-2021-22930
- https://www.suse.com/security/cve/CVE-2021-22931
- https://www.suse.com/security/cve/CVE-2021-22939
- https://www.suse.com/security/cve/CVE-2021-22940
- https://www.suse.com/security/cve/CVE-2021-3672