nodejs-nodemon-2.0.19-1.el9, nodejs-16.16.0-1.el9

エラータID: AXSA:2022-4073:01

Release date: 
Wednesday, November 16, 2022 - 13:03
Subject: 
nodejs-nodemon-2.0.19-1.el9, nodejs-16.16.0-1.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

The following packages have been upgraded to a later upstream version: nodejs (16.16.0), nodejs-nodemon (2.0.19).

Security Fix(es):

* nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788)
* nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)
* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)
* normalize-url: ReDoS for data URLs (CVE-2021-33502)
* nodejs: npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace (CVE-2022-29244)
* nodejs: DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212)
* nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding (CVE-2022-32213)
* nodejs: HTTP request smuggling due to improper delimiting of header fields (CVE-2022-32214)
* nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (CVE-2022-32215)
* got: missing verification of requested URLs allows redirects to UNIX sockets (CVE-2022-33987)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* nodejs:16/nodejs: Rebase to the latest Nodejs 16 release
* nodejs: Specify --with-default-icu-data-dir when using bootstrap build

CVE-2020-28469
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
CVE-2020-7788
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
CVE-2021-33502
The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
CVE-2021-3807
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
CVE-2022-29244
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.16.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
CVE-2022-32213
The llhttp parser

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nodejs-nodemon-2.0.19-1.el9.src.rpm
    MD5: e61cdffacf2556f839cd276c847a16b6
    SHA-256: ae1c27c0b2b47a0846f003e4783dc36ae82b07b49164212d399e3a4509969977
    Size: 938.03 kB
  2. nodejs-16.16.0-1.el9.src.rpm
    MD5: 177a558c2d13b298bbdd0a53680d6bab
    SHA-256: 9e976ca7207b4b9ce7f75695b9f089aa6af103df7f5c51ee760bdc6db08fde25
    Size: 67.65 MB

Asianux Server 9 for x86_64
  1. nodejs-nodemon-2.0.19-1.el9.noarch.rpm
    MD5: 0ff6827210f991cfc6b05cd84712b662
    SHA-256: b3ec7418e7bd1146a793c0472e6446be16f99c4526c0a072c5af0e189f804acf
    Size: 506.00 kB
  2. nodejs-16.16.0-1.el9.x86_64.rpm
    MD5: e177474e8343454d61668809f6f3c145
    SHA-256: 73e3cba79e8cb14d3f2e8a949fbbfdb17ef500970743ba60c4850db0ea41c444
    Size: 99.41 kB
  3. nodejs-docs-16.16.0-1.el9.noarch.rpm
    MD5: dc469330030db82aa2ce8bffa0b2b61e
    SHA-256: 06af66e7e726506d45d6075b8037b87535debfef2f814f55728548669fff873c
    Size: 6.80 MB
  4. nodejs-full-i18n-16.16.0-1.el9.x86_64.rpm
    MD5: 76b1601a66203f04845d7e9a93e114a3
    SHA-256: 15ff59697ec8a684493c935509563a74db39629657ea47eb8d6a632c961eb508
    Size: 8.06 MB
  5. nodejs-libs-16.16.0-1.el9.x86_64.rpm
    MD5: 630bbafa1fdc67bf2f2a714a3b01b5ff
    SHA-256: b9a4d3686b796a5e77c3e2d2e96428d8cee6a51221deb0f0612bc095f58961dd
    Size: 14.40 MB
  6. npm-8.11.0-1.16.16.0.1.el9.x86_64.rpm
    MD5: b774b88f9f416b72cb959bb95c8ff044
    SHA-256: 1adc3c38388e09ebbe624091aaadecd3ea8d7d10ebd216c3a86ed0868b4df154
    Size: 1.72 MB
  7. nodejs-libs-16.16.0-1.el9.i686.rpm
    MD5: d24d696096707d0886b4403955a265e0
    SHA-256: c09b4f9de1e26e521cab4342c4bc47d1dbae1fffbcd27f77c1f4304c982c0cc0
    Size: 15.05 MB