DSA-5528-1 node-babel7 -- security update

Related Vulnerabilities: CVE-2023-45133  

William Khem-Marquez discovered that using malicious plugins for the the Babel JavaScript compiler could result in arbitrary code execution during compilation For the oldstable distribution (bullseye), this problem has been fixed in version 7.12.12+~cs150.141.84-6+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 7.20.15+ds1+~cs214.269.168-3+deb12u1. We recommend that you upgrade your node-babel7 packages. For the detailed security status of node-babel7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/node-babel7

Debian Security Advisory

DSA-5528-1 node-babel7 -- security update

Date Reported:
16 Oct 2023
Affected Packages:
node-babel7
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 1053880.
In Mitre's CVE dictionary: CVE-2023-45133.
More information:

William Khem-Marquez discovered that using malicious plugins for the the Babel JavaScript compiler could result in arbitrary code execution during compilation

For the oldstable distribution (bullseye), this problem has been fixed in version 7.12.12+~cs150.141.84-6+deb11u1.

For the stable distribution (bookworm), this problem has been fixed in version 7.20.15+ds1+~cs214.269.168-3+deb12u1.

We recommend that you upgrade your node-babel7 packages.

For the detailed security status of node-babel7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/node-babel7