Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22930)
nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940)
c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672)
nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931)
nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803)
nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804)
nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939)
nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):