Une assistance commerciale pour les versions ayant dépassé la phase de maintenance LTS est disponible via notre partenaire HeroDevs, dans le cadre du programme de pérennité de l'écosystème OpenJS
April 2021 Security Releases
DB
Daniel Bevenius
(Update 6-Apr-2021) Security releases available
Updates are now available for v10,x, v12.x, v14.x and v15.x Node.js release lines for the following issues.
OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High) (CVE-2021-3450)
This is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20210325.txt
Impacts:
- All versions of the 15.x, 14.x, 12.x and 10.x releases lines
OpenSSL - NULL pointer deref in signature_algorithms processing (High) (CVE-2021-3449)
This is a vulnerability in OpenSSL which may be exploited through Node.js. You can read more about it in https://www.openssl.org/news/secadv/20210325.txt
Impacts:
- All versions of the 15.x, 14.x, 12.x and 10.x releases lines
npm upgrade - Update y18n to fix Prototype-Pollution (High) (CVE-2020-7774)
This is a vulnerability in the y18n npm module which may be exploited by prototype pollution. You can read more about it in https://github.com/advisories/GHSA-c4w7-xm78-47vh
Impacts:
- All versions of the 14.x, 12.x and 10.x releases lines