MGASA-2024-0110

Source
https://advisories.mageia.org/MGASA-2024-0110.html
Import Source
https://advisories.mageia.org/MGASA-2024-0110.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0110
Related
Published
2024-04-05T18:24:25Z
Modified
2024-04-05T18:07:54Z
Summary
Updated nodejs packages fix security vulnerabilities
Details

Nodejs 20.12.1 release fixes 2 CVE: * CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High) * CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium)

References
Credits

Affected packages

Mageia:9 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/mageia/nodejs?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20.12.1-1.mga9

Ecosystem specific

{
    "section": "core"
}