Security update for nodejs10
This update for nodejs10 fixes the following issues: - CVE-2021-3672: Fixed missing input validation on hostnames (bsc#1188881). - CVE-2021-22930: Fixed use after free on close http2 on stream canceling (bsc#1188917). - CVE-2021-22939: Fixed incomplete validation of rejectUnauthorized parameter (bsc#1189369). - CVE-2021-22931: Fixed improper handling of untypical characters in domain names (bsc#1189370).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs10 fixes the following issues: - CVE-2021-3672: Fixed missing input validation on hostnames (bsc#1188881). - CVE-2021-22930: Fixed use after free on close http2 on stream canceling (bsc#1188917). - CVE-2021-22939: Fixed incomplete validation of rejectUnauthorized parameter (bsc#1189369). - CVE-2021-22931: Fixed improper handling of untypical characters in domain names (bsc#1189370).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1188881
- https://bugzilla.suse.com/1188917
- https://bugzilla.suse.com/1189369
- https://bugzilla.suse.com/1189370
- https://www.suse.com/security/cve/CVE-2021-22930
- https://www.suse.com/security/cve/CVE-2021-22931
- https://www.suse.com/security/cve/CVE-2021-22939
- https://www.suse.com/security/cve/CVE-2021-3672
- https://www.suse.com/support/update/announcement/2021/suse-su-20212823-1/