Advisories ยป MGASA-2023-0299

Updated nodejs packages fix security vulnerabilities

Publication date: 22 Oct 2023
Modification date: 22 Oct 2023
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-44487 , CVE-2023-45143 , CVE-2023-38552 , CVE-2023-39333

Description

This is a security release. The following CVEs are fixed in this
release:

CVE-2023-44487: nghttp2 Security Release (High)
CVE-2023-45143: undici Security Release (High)
CVE-2023-38552: Integrity checks according to policies can be
circumvented (Medium)
CVE-2023-39333: Code injection via WebAssembly export names (Low)

More detailed information on each of the vulnerabilities can be found in
October 2023 Security Releases blog post.
                

References

SRPMS

9/core