node: Friday October 13 2023 Security Releases 22429/head
authorHirokazu MORIKAWA <morikw2@gmail.com>
Tue, 17 Oct 2023 00:26:24 +0000 (09:26 +0900)
committerJosef Schlehofer <pepe.schlehofer@gmail.com>
Wed, 18 Oct 2023 08:34:12 +0000 (10:34 +0200)
commit3658011d9da7d5ef2cc581a9ad05ada6391184ae
treef67618b8b81065b41b9d4c5bea3d72095a98cd42
parentf8753b9705a8c119e71fe2bd022e116da59ab440
node: Friday October 13 2023 Security Releases

This is a security release.
Notable Changes
The following CVEs are fixed in this release:
* CVE-2023-44487: nghttp2 Security Release (High) (Depends on shared library provided by OpenWrt)
* CVE-2023-45143: undici Security Release (High)
* CVE-2023-38552: Integrity checks according to policies can be circumvented (Medium)
* CVE-2023-39333: Code injection via WebAssembly export names (Low)
More detailed information on each of the vulnerabilities can be found in October 2023 Security Releases blog post.

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
(cherry picked from commit 9101a21e535d2247b3fb85e0660f7bb0dd4a4290)
lang/node/Makefile