Security update for nodejs12
This update for nodejs12 fixes the following issues: - CVE-2021-44531: Fixed improper handling of URI Subject Alternative Names (bsc#1194511). - CVE-2021-44532: Fixed certificate Verification Bypass via String Injection (bsc#1194512). - CVE-2021-44533: Fixed incorrect handling of certificate subject and issuer fields (bsc#1194513). - CVE-2022-21824: Fixed prototype pollution via console.table properties (bsc#1194514). - CVE-2021-22959: Fixed HTTP Request Smuggling due to spaced in headers(bsc#1191601). - CVE-2021-22960: Fixed HTTP Request Smuggling when parsing the body (bsc#1191602). - CVE-2021-37701: Fixed arbitrary file creation and overwrite vulnerability in nodejs-tar (bsc#1190057). - CVE-2021-37712: Fixed arbitrary file creation and overwrite vulnerability in nodejs-tar (bsc#1190056). - CVE-2021-37713: Fixed arbitrary file creation/overwrite and arbitrary code execution vulnerability in nodejs-tar (bsc#1190055). - CVE-2021-39134: Fixed symlink following vulnerability in nodejs-arborist (bsc#1190054). - CVE-2021-39135: Fixed symlink following vulnerability in nodejs-arborist (bsc#1190053).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs12 fixes the following issues: - CVE-2021-44531: Fixed improper handling of URI Subject Alternative Names (bsc#1194511). - CVE-2021-44532: Fixed certificate Verification Bypass via String Injection (bsc#1194512). - CVE-2021-44533: Fixed incorrect handling of certificate subject and issuer fields (bsc#1194513). - CVE-2022-21824: Fixed prototype pollution via console.table properties (bsc#1194514). - CVE-2021-22959: Fixed HTTP Request Smuggling due to spaced in headers(bsc#1191601). - CVE-2021-22960: Fixed HTTP Request Smuggling when parsing the body (bsc#1191602). - CVE-2021-37701: Fixed arbitrary file creation and overwrite vulnerability in nodejs-tar (bsc#1190057). - CVE-2021-37712: Fixed arbitrary file creation and overwrite vulnerability in nodejs-tar (bsc#1190056). - CVE-2021-37713: Fixed arbitrary file creation/overwrite and arbitrary code execution vulnerability in nodejs-tar (bsc#1190055). - CVE-2021-39134: Fixed symlink following vulnerability in nodejs-arborist (bsc#1190054). - CVE-2021-39135: Fixed symlink following vulnerability in nodejs-arborist (bsc#1190053).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1190053
- https://bugzilla.suse.com/1190054
- https://bugzilla.suse.com/1190055
- https://bugzilla.suse.com/1190056
- https://bugzilla.suse.com/1190057
- https://bugzilla.suse.com/1191601
- https://bugzilla.suse.com/1191602
- https://bugzilla.suse.com/1194511
- https://bugzilla.suse.com/1194512
- https://bugzilla.suse.com/1194513
- https://bugzilla.suse.com/1194514
- https://www.suse.com/security/cve/CVE-2021-22959
- https://www.suse.com/security/cve/CVE-2021-22960
- https://www.suse.com/security/cve/CVE-2021-37701
- https://www.suse.com/security/cve/CVE-2021-37712
- https://www.suse.com/security/cve/CVE-2021-37713
- https://www.suse.com/security/cve/CVE-2021-39134
- https://www.suse.com/security/cve/CVE-2021-39135
- https://www.suse.com/security/cve/CVE-2021-44531
- https://www.suse.com/security/cve/CVE-2021-44532
- https://www.suse.com/security/cve/CVE-2021-44533
- https://www.suse.com/security/cve/CVE-2022-21824
- https://www.suse.com/support/update/announcement/2022/suse-su-20220101-1/