OESA-2021-1409
Dashboard / Vulnerabilities / OESA-2021-1409
Summary: nodejs security update
Details: Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Security Fix(es): Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.(CVE-2021-22930)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1409, https://nvd.nist.gov/vuln/detail/CVE-2021-22930
Affected packages
Package
Name: nodejs
Purl: pkg:rpm/openEuler/nodejs&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
