[Git][security-tracker-team/security-tracker][master] CVE-2022-21704/node-log4js, CVE-2021-3803/node-nth-check,...

Sylvain Beucler (@beuc) beuc at debian.org
Sat Feb 5 22:02:09 GMT 2022



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e0cc5c0a by Sylvain Beucler at 2022-02-05T23:01:42+01:00
CVE-2022-21704/node-log4js, CVE-2021-3803/node-nth-check, CVE-2021-33623/node-trim-newlines: stretch end-of-life

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14571,6 +14571,7 @@ CVE-2022-21704 (log4js-node is a port of log4js to node.js. In affected versions
 	- node-log4js 6.4.1+~cs8.3.5-1
 	[bullseye] - node-log4js <no-dsa> (Minor issue)
 	[buster] - node-log4js <no-dsa> (Minor issue)
+	[stretch] - node-log4js <end-of-life> (Nodejs in stretch not covered by security support)
 	NOTE: https://github.com/log4js-node/log4js-node/pull/1141 (v6.4.1)
 	NOTE: https://github.com/log4js-node/streamroller/pull/87
 	NOTE: https://github.com/log4js-node/log4js-node/security/advisories/GHSA-82v2-mx6x-wq7q
@@ -24966,6 +24967,7 @@ CVE-2021-41079 (Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1
 	NOTE: https://github.com/apache/tomcat/commit/b90d4fc1ff44f30e4b3aba622ba6677e3f003822 (8.5.64)
 CVE-2021-3803 (nth-check is vulnerable to Inefficient Regular Expression Complexity ...)
 	- node-nth-check 2.0.1-1
+	[stretch] - node-nth-check <end-of-life> (Nodejs in stretch not covered by security support)
 	NOTE: https://github.com/fb55/nth-check/commit/9894c1d2010870c351f66c6f6efcf656e26bb726 (v2.0.1)
 	NOTE: https://huntr.dev/bounties/8cf8cc06-d2cf-4b4e-b42c-99fafb0b04d0/
 	NOTE: https://github.com/advisories/GHSA-rp65-9cf3-cjxr
@@ -43134,6 +43136,7 @@ CVE-2021-33624 (In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a b
 	NOTE: https://www.openwall.com/lists/oss-security/2021/06/21/1
 CVE-2021-33623 (The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.j ...)
 	- node-trim-newlines 3.0.0+~3.0.0-1
+	[stretch] - node-trim-newlines <end-of-life> (Nodejs in stretch not covered by security support)
 	NOTE: https://github.com/advisories/GHSA-7p7h-4mm5-852v
 CVE-2021-33622 (Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, h ...)
 	- singularity-container <unfixed> (bug #990201)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0cc5c0a905880532471da22d7e1e49d41ae2e07

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0cc5c0a905880532471da22d7e1e49d41ae2e07
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220205/8593dc4e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list