FlawAtlas
Search the atlas
SUSE-SU-2022:1717-1 Not scored

Security update for nodejs10

This update for nodejs10 fixes the following issues: - CVE-2021-23343: Fixed ReDoS via splitDeviceRe, splitTailRe and splitPathRe (bsc#1192153). - CVE-2021-32803: Fixed insufficient symlink protection in node-tar allowing arbitrary file creation and overwrite (bsc#1191963). - CVE-2021-32804: Fixed insufficient absolute path sanitization in node-tar allowing arbitrary file creation and overwrite (bsc#1191962). - CVE-2021-3918: Fixed improper controlled modification of object prototype attributes in json-schema (bsc#1192696). - CVE-2021-3807: Fixed regular expression denial of service (ReDoS) matching ANSI escape codes in node-ansi-regex (bsc#1192154). - CVE-2022-21824: Fixed prototype pollution via console.table (bsc#1194514). - CVE-2021-44906: Fixed prototype pollution in npm dependency (bsc#1198247). - CVE-2021-44907: Fixed insuficient sanitation in npm dependency (bsc#1197283). - CVE-2022-0235: Fixed passing of cookie data and sensitive headers to different hostnames in node-fetch-npm (bsc#1194819).

Exploit probability Not scored
Published May 17, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 6 nodejs10
SUSE:Enterprise Storage 7 nodejs10
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS nodejs10
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS nodejs10
SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS nodejs10
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS nodejs10
SUSE:Linux Enterprise High Performance Computing 15-ESPOS nodejs10
SUSE:Linux Enterprise High Performance Computing 15-LTSS nodejs10
SUSE:Linux Enterprise Server 15 SP1-BCL nodejs10
SUSE:Linux Enterprise Server 15 SP1-LTSS nodejs10
SUSE:Linux Enterprise Server 15 SP2-BCL nodejs10
SUSE:Linux Enterprise Server 15 SP2-LTSS nodejs10
SUSE:Linux Enterprise Server 15-LTSS nodejs10
SUSE:Linux Enterprise Server for SAP Applications 15 nodejs10
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 nodejs10
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 nodejs10
SUSE:Manager Proxy 4.1 nodejs10
SUSE:Manager Retail Branch Server 4.1 nodejs10
SUSE:Manager Server 4.1 nodejs10
openSUSE:Leap 15.3 nodejs10
openSUSE:Leap 15.4 nodejs10

03 / CONNECTIONS

Connected vulnerabilities

related CVE-2021-44907
upstream CVE-2021-44907

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2022:1717-1

This update for nodejs10 fixes the following issues: - CVE-2021-23343: Fixed ReDoS via splitDeviceRe, splitTailRe and splitPathRe (bsc#1192153). - CVE-2021-32803: Fixed insufficient symlink protection in node-tar allowing arbitrary file creation and overwrite (bsc#1191963). - CVE-2021-32804: Fixed insufficient absolute path sanitization in node-tar allowing arbitrary file creation and overwrite (bsc#1191962). - CVE-2021-3918: Fixed improper controlled modification of object prototype attributes in json-schema (bsc#1192696). - CVE-2021-3807: Fixed regular expression denial of service (ReDoS) matching ANSI escape codes in node-ansi-regex (bsc#1192154). - CVE-2022-21824: Fixed prototype pollution via console.table (bsc#1194514). - CVE-2021-44906: Fixed prototype pollution in npm dependency (bsc#1198247). - CVE-2021-44907: Fixed insuficient sanitation in npm dependency (bsc#1197283). - CVE-2022-0235: Fixed passing of cookie data and sensitive headers to different hostnames in node-fetch-npm (bsc#1194819).

View original source

05 / REFERENCES

Further evidence