MGASA-2024-0282

Source
https://advisories.mageia.org/MGASA-2024-0282.html
Import Source
https://advisories.mageia.org/MGASA-2024-0282.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0282
Related
Published
2024-08-28T17:11:44Z
Modified
2024-08-28T16:48:29Z
Summary
Updated nodejs & yarnpkg packages fix security vulnerabilities
Details

Nodejs 22 is the new active LTS branch and 5 CVE are fixed. CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980 (High) CVE-2024-22020 - Bypass network import restriction via data URL (Medium) CVE-2024-22018 - fs.lstat bypasses permission model (Low) CVE-2024-36137 - fs.fchown/fchmod bypasses permission model (Low) CVE-2024-37372 - Permission model improperly processes UNC paths (Low) yarn package is updated with npm 10.8.2

References
Credits

Affected packages