Security update for nodejs14
This update for nodejs14 fixes the following issues: Security issues fixed: * CVE-2023-46809: Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) (bsc#1219997). * CVE-2024-22019: http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (bsc#1219993). * CVE-2024-22025: Denial of Service by resource exhaustion in fetch() brotli decoding (bsc#1220014). * CVE-2024-24806: fix improper domain lookup that potentially leads to SSRF attacks (bsc#1219724).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs14 fixes the following issues: Security issues fixed: * CVE-2023-46809: Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) (bsc#1219997). * CVE-2024-22019: http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (bsc#1219993). * CVE-2024-22025: Denial of Service by resource exhaustion in fetch() brotli decoding (bsc#1220014). * CVE-2024-24806: fix improper domain lookup that potentially leads to SSRF attacks (bsc#1219724).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1219993
- https://bugzilla.suse.com/1219997
- https://bugzilla.suse.com/1220014
- https://bugzilla.suse.com/1220053
- https://www.suse.com/security/cve/CVE-2023-46809
- https://www.suse.com/security/cve/CVE-2024-22019
- https://www.suse.com/security/cve/CVE-2024-22025
- https://www.suse.com/security/cve/CVE-2024-24806
- https://www.suse.com/support/update/announcement/2024/suse-su-20240732-1/