Security update for nodejs18
This update for nodejs18 fixes the following issues: - Update to version 18.18.2 - CVE-2023-44487: Fixed the Rapid Reset attack in nghttp2. (bsc#1216190) - CVE-2023-45143: Fixed a cookie leakage in undici. (bsc#1216205) - CVE-2023-38552: Fixed an integrity checks according to policies that could be circumvented. (bsc#1216272) - CVE-2023-39333: Fixed a code injection via WebAssembly export names. (bsc#1216273)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs18 fixes the following issues: - Update to version 18.18.2 - CVE-2023-44487: Fixed the Rapid Reset attack in nghttp2. (bsc#1216190) - CVE-2023-45143: Fixed a cookie leakage in undici. (bsc#1216205) - CVE-2023-38552: Fixed an integrity checks according to policies that could be circumvented. (bsc#1216272) - CVE-2023-39333: Fixed a code injection via WebAssembly export names. (bsc#1216273)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1216190
- https://bugzilla.suse.com/1216205
- https://bugzilla.suse.com/1216272
- https://bugzilla.suse.com/1216273
- https://www.suse.com/security/cve/CVE-2023-38552
- https://www.suse.com/security/cve/CVE-2023-39333
- https://www.suse.com/security/cve/CVE-2023-44487
- https://www.suse.com/security/cve/CVE-2023-45143
- https://www.suse.com/support/update/announcement/2023/suse-su-20234133-1/