node: February 14 2024 Security Releases
authorHirokazu MORIKAWA <morikw2@gmail.com>
Fri, 16 Feb 2024 07:06:52 +0000 (16:06 +0900)
committerTianling Shen <cnsztl@gmail.com>
Sat, 17 Feb 2024 05:27:56 +0000 (13:27 +0800)
commitf12547cf1ff8b9c36c542bf22b165196b9e86d5a
treeba37516d655d57b5dc95ba1c20cfb23f10f54830
parent9d8882fe4979d0b95b21ea5365e6f08ba205afc4
node: February 14 2024 Security Releases

Update to v18.19.1
This is a security release.

Notable changes
* CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
* CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
* CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
* CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
* undici version 5.28.3
* npm version 10.2.4

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
lang/node/Makefile