Moderate: nodejs:12 security and bug fix update

Synopsis

Moderate: nodejs:12 security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

The following packages have been upgraded to a later upstream version: nodejs (12.18.4).

Security Fix(es):

  • nodejs-dot-prop: prototype pollution (CVE-2020-8116)
  • nodejs: HTTP request smuggling due to CR-to-Hyphen conversion (CVE-2020-8201)
  • npm: Sensitive information exposure through logs (CVE-2020-15095)
  • libuv: buffer overflow in realpath (CVE-2020-8252)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • The nodejs:12/development module is not installable (BZ#1883966)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.2 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.2 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.2 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.2 aarch64
  • Red Hat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Enterprise Linux Server - Update Services for SAP Solutions 8.2 x86_64

Fixes

  • BZ - 1856875 - CVE-2020-15095 npm: Sensitive information exposure through logs
  • BZ - 1868196 - CVE-2020-8116 nodejs-dot-prop: prototype pollution
  • BZ - 1879311 - CVE-2020-8201 nodejs: HTTP request smuggling due to CR-to-Hyphen conversion
  • BZ - 1879315 - CVE-2020-8252 libuv: buffer overflow in realpath
  • BZ - 1883966 - The nodejs:12/development module is not installable [rhel-8.2.0.z]

CVEs

References