SUSE-SU-2022:3250-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3250-1
SUSE-SU-2022:3250-1
Summary: Security update for nodejs16
Details: This update for nodejs16 fixes the following issues: - CVE-2022-35949: Fixed SSRF when an application takes in user input into the path/pathname option of undici.request (bsc#1202382). - CVE-2022-35948: Fixed CRLF injection via Content-Type (bsc#1202383). - CVE-2022-29244: Fixed npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace (bsc#1200517). - CVE-2022-31150: Fixed CRLF injection in node-undici (bsc#1201710). Bugfixes: - Enable crypto-policies for SLE15 SP4+ and TW (bsc#1200303)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223250-1/, https://bugzilla.suse.com/1200303, https://bugzilla.suse.com/1200517, https://bugzilla.suse.com/1201710, https://bugzilla.suse.com/1202382, https://bugzilla.suse.com/1202383, https://www.suse.com/security/cve/CVE-2022-29244, https://www.suse.com/security/cve/CVE-2022-31150, https://www.suse.com/security/cve/CVE-2022-35948, https://www.suse.com/security/cve/CVE-2022-35949
Affected packages
Package
Name: nodejs16
Purl: pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
