ELSA-2023-5360

ELSA-2023-5360 - nodejs:16 security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2023-09-28

Description


nodejs
[1:16.20.2-2]
- Rebase to 16.20.2
Resolves: rhbz#2231866
Resolves: CVE-2023-32002 CVE-2023-32006 CVE-2023-32559

nodejs-nodemon
[3.0.1-1]
- Rebase to 3.0.1
Resolves: CVE-2022-25883

nodejs-packaging
[26-1]
- nodejs.prov: find namespaced bundled dependencies
- Apply https://src.fedoraproject.org/rpms/nodejs-packaging/c/e24e7df


Related CVEs


CVE-2022-25883
CVE-2023-32559
CVE-2023-32002
CVE-2023-32006

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) nodejs-16.20.2-2.module+el8.8.0+21172+0baa0bae.src.rpm2f1aabad05e4ca41949a59e2d6443525df7753894a2983dd39a0a41eb2095b7f-ol8_aarch64_appstream
nodejs-nodemon-3.0.1-1.module+el8.8.0+21172+0baa0bae.src.rpmeb6059a7663c41ca4b7163490ee2dd8f74bfa19ad2badc8d7cbd65431fb80ef9-ol8_aarch64_appstream
nodejs-packaging-26-1.module+el8.8.0+21172+0baa0bae.src.rpm7b42d1a9dfa043d2be1771b870ce95419d06a571ca1dd60297f0d518d4387b51-ol8_aarch64_appstream
nodejs-16.20.2-2.module+el8.8.0+21172+0baa0bae.aarch64.rpmb99acc9ef5dbd71ac5c208b807678a239d22d190ae8076ba968919790b42a000-ol8_aarch64_appstream
nodejs-devel-16.20.2-2.module+el8.8.0+21172+0baa0bae.aarch64.rpmffcea81ff6b299c4cb664c52d7c29fb86add7c7f58d5c1662b94b00ba0dcf311-ol8_aarch64_appstream
nodejs-docs-16.20.2-2.module+el8.8.0+21172+0baa0bae.noarch.rpm68850d63f2654f6b99596360a3f00805d05f5d920c00ecb959ffb489fe870b50-ol8_aarch64_appstream
nodejs-full-i18n-16.20.2-2.module+el8.8.0+21172+0baa0bae.aarch64.rpm724542f7f219ce0b8372a66148338438ae8f9da9ac6582e46351f1e137e01721-ol8_aarch64_appstream
nodejs-nodemon-3.0.1-1.module+el8.8.0+21172+0baa0bae.noarch.rpm688f4bfcfacf92538b037866ce03c9e49c31d552b6763c2e642d331e0270d402-ol8_aarch64_appstream
nodejs-packaging-26-1.module+el8.8.0+21172+0baa0bae.noarch.rpm4e9a96e5b27535632eae91c443149d73ff5cfd603f380a79cf6d5d7b2fefc6d6-ol8_aarch64_appstream
npm-8.19.4-1.16.20.2.2.module+el8.8.0+21172+0baa0bae.aarch64.rpm3eeba14d8cf8ee0bf907196c907345105ae037d0669c57f79dfa0115dd4e9c20-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) nodejs-16.20.2-2.module+el8.8.0+21172+0baa0bae.src.rpm2f1aabad05e4ca41949a59e2d6443525df7753894a2983dd39a0a41eb2095b7f-ol8_x86_64_appstream
nodejs-nodemon-3.0.1-1.module+el8.8.0+21172+0baa0bae.src.rpmeb6059a7663c41ca4b7163490ee2dd8f74bfa19ad2badc8d7cbd65431fb80ef9-ol8_x86_64_appstream
nodejs-packaging-26-1.module+el8.8.0+21172+0baa0bae.src.rpm7b42d1a9dfa043d2be1771b870ce95419d06a571ca1dd60297f0d518d4387b51-ol8_x86_64_appstream
nodejs-16.20.2-2.module+el8.8.0+21172+0baa0bae.x86_64.rpmf1b34d6d546f8d02142fed330f22f97c3d5196192626b3a05593d94f001339ab-ol8_x86_64_appstream
nodejs-devel-16.20.2-2.module+el8.8.0+21172+0baa0bae.x86_64.rpm89f4af89e4e32db6fe469fd5c7dc257038c6ab4f1ba58b116bb8217b2c379fa5-ol8_x86_64_appstream
nodejs-docs-16.20.2-2.module+el8.8.0+21172+0baa0bae.noarch.rpm68850d63f2654f6b99596360a3f00805d05f5d920c00ecb959ffb489fe870b50-ol8_x86_64_appstream
nodejs-full-i18n-16.20.2-2.module+el8.8.0+21172+0baa0bae.x86_64.rpm9f44386aa9e623710eeb78d1cbdd21bbf3f529939283da0f5622d14140e51f76-ol8_x86_64_appstream
nodejs-nodemon-3.0.1-1.module+el8.8.0+21172+0baa0bae.noarch.rpm688f4bfcfacf92538b037866ce03c9e49c31d552b6763c2e642d331e0270d402-ol8_x86_64_appstream
nodejs-packaging-26-1.module+el8.8.0+21172+0baa0bae.noarch.rpm4e9a96e5b27535632eae91c443149d73ff5cfd603f380a79cf6d5d7b2fefc6d6-ol8_x86_64_appstream
npm-8.19.4-1.16.20.2.2.module+el8.8.0+21172+0baa0bae.x86_64.rpm0721101be9ea63407d249a72e2b7deefcae0552001f98c8b969de71cef0eacb8-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete