[Git][security-tracker-team/security-tracker][master] CVE-2022-21704/node-log4js, CVE-2021-3803/node-nth-check,...
Sylvain Beucler (@beuc)
beuc at debian.org
Sat Feb 5 22:02:09 GMT 2022
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e0cc5c0a by Sylvain Beucler at 2022-02-05T23:01:42+01:00
CVE-2022-21704/node-log4js, CVE-2021-3803/node-nth-check, CVE-2021-33623/node-trim-newlines: stretch end-of-life
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -14571,6 +14571,7 @@ CVE-2022-21704 (log4js-node is a port of log4js to node.js. In affected versions
- node-log4js 6.4.1+~cs8.3.5-1
[bullseye] - node-log4js <no-dsa> (Minor issue)
[buster] - node-log4js <no-dsa> (Minor issue)
+ [stretch] - node-log4js <end-of-life> (Nodejs in stretch not covered by security support)
NOTE: https://github.com/log4js-node/log4js-node/pull/1141 (v6.4.1)
NOTE: https://github.com/log4js-node/streamroller/pull/87
NOTE: https://github.com/log4js-node/log4js-node/security/advisories/GHSA-82v2-mx6x-wq7q
@@ -24966,6 +24967,7 @@ CVE-2021-41079 (Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1
NOTE: https://github.com/apache/tomcat/commit/b90d4fc1ff44f30e4b3aba622ba6677e3f003822 (8.5.64)
CVE-2021-3803 (nth-check is vulnerable to Inefficient Regular Expression Complexity ...)
- node-nth-check 2.0.1-1
+ [stretch] - node-nth-check <end-of-life> (Nodejs in stretch not covered by security support)
NOTE: https://github.com/fb55/nth-check/commit/9894c1d2010870c351f66c6f6efcf656e26bb726 (v2.0.1)
NOTE: https://huntr.dev/bounties/8cf8cc06-d2cf-4b4e-b42c-99fafb0b04d0/
NOTE: https://github.com/advisories/GHSA-rp65-9cf3-cjxr
@@ -43134,6 +43136,7 @@ CVE-2021-33624 (In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a b
NOTE: https://www.openwall.com/lists/oss-security/2021/06/21/1
CVE-2021-33623 (The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.j ...)
- node-trim-newlines 3.0.0+~3.0.0-1
+ [stretch] - node-trim-newlines <end-of-life> (Nodejs in stretch not covered by security support)
NOTE: https://github.com/advisories/GHSA-7p7h-4mm5-852v
CVE-2021-33622 (Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, h ...)
- singularity-container <unfixed> (bug #990201)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0cc5c0a905880532471da22d7e1e49d41ae2e07
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0cc5c0a905880532471da22d7e1e49d41ae2e07
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220205/8593dc4e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list