FlawAtlas
Search the atlas
OPENSUSE-SU-2022:0112-1 Not scored

Security update for nodejs14

This update for nodejs14 fixes the following issues: - CVE-2021-44531: Fixed improper handling of URI Subject Alternative Names (bsc#1194511). - CVE-2021-44532: Fixed certificate Verification Bypass via String Injection (bsc#1194512). - CVE-2021-44533: Fixed incorrect handling of certificate subject and issuer fields (bsc#1194513). - CVE-2022-21824: Fixed prototype pollution via console.table properties (bsc#1194514).

Exploit probability Not scored
Published January 18, 2022
Required by Not available
Last source change May 7, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Package Hub 15 SP3 chromium
openSUSE:Leap 15.3 chromium
openSUSE:Leap 15.3 nodejs14

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2022:0112-1

This update for nodejs14 fixes the following issues: - CVE-2021-44531: Fixed improper handling of URI Subject Alternative Names (bsc#1194511). - CVE-2021-44532: Fixed certificate Verification Bypass via String Injection (bsc#1194512). - CVE-2021-44533: Fixed incorrect handling of certificate subject and issuer fields (bsc#1194513). - CVE-2022-21824: Fixed prototype pollution via console.table properties (bsc#1194514).

View original source

05 / REFERENCES

Further evidence