node: August 2023 Security Releases
authorHirokazu MORIKAWA <morikw2@gmail.com>
Thu, 10 Aug 2023 05:23:46 +0000 (14:23 +0900)
committerHannu Nyman <hannu.nyman@iki.fi>
Thu, 10 Aug 2023 17:03:16 +0000 (20:03 +0300)
commit9ddc94bbe2e5fe9a79dd8ffa6983978c9f5641d5
tree20bfefa7a095c16ff56fdf4e84c3a1cb9d88a6f1
parent76fccd9ead6e055bb293f62ba681382c0f06e2d0
node: August 2023 Security Releases

Update to v16.20.2
This is a security release.

Notable Changes
The following CVEs are fixed in this release:
* CVE-2023-32002: Policies can be bypassed via Module._load (High)
* CVE-2023-32006: Policies can be bypassed by module.constructor.createRequire (Medium)
* CVE-2023-32559: Policies can be bypassed via process.binding (Medium)
* OpenSSL Security Releases  (Depends on shared library provided by OpenWrt)
    * OpenSSL security advisory 14th July.
    * OpenSSL security advisory 19th July.
    * OpenSSL security advisory 31st July

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
lang/node/Makefile