Lucene search

K
oraclelinuxOracleLinuxELSA-2024-1688
HistoryApr 08, 2024 - 12:00 a.m.

nodejs:20 security update

2024-04-0800:00:00
linux.oracle.com
18
nodejs
security update
cve-2024-21892
cve-2024-21896
cve-2024-22017
cve-2024-22019
cve-2023-46809
cve-2024-21890
cve-2024-21891

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.9

Confidence

High

EPSS

0

Percentile

16.3%

nodejs
[1:20.11.1-1]

  • Rebase to version 20.11.1
  • Fixes: CVE-2024-21892 CVE-2024-21896 CVE-2024-22017 CVE-2024-22019 (high)
  • Fixes: CVE-2023-46809 CVE-2024-21890 CVE-2024-21891 (medium)
    nodejs-nodemon
    nodejs-packaging

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.9

Confidence

High

EPSS

0

Percentile

16.3%