[Git][security-tracker-team/security-tracker][master] add nodejs issue (seems missed in the blog post) and commit references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Feb 23 13:52:56 GMT 2024



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0186c260 by Moritz Muehlenhoff at 2024-02-23T14:52:03+01:00
add nodejs issue (seems missed in the blog post) and commit references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,8 @@
+CVE-2024-22025
+	- nodejs 18.19.1+dfsg-1
+	NOTE: https://nodejs.org/en/blog/release/v18.19.1
+	NOTE: https://github.com/nodejs/node/commit/f31d47e135973746c4f490d5eb635eded8bb3dda (v18.x)
+	NOTE: https://github.com/nodejs/node/commit/9052ef43dc2d1b0db340591a9bc9e45a25c01d90 (main)
 CVE-2024-26593 [i2c: i801: Fix block process call transactions]
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/c1c9d0f6f7f1dbf29db996bd8e166242843a5f21 (6.8-rc5)
@@ -1571,6 +1576,8 @@ CVE-2024-21896 (The permission model protects itself against path traversal atta
 CVE-2024-22019 (A vulnerability in Node.js HTTP servers allows an attacker to send a s ...)
 	- nodejs 18.19.1+dfsg-1 (bug #1064055)
 	NOTE: https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-cve-2024-22019---high
+	NOTE: https://github.com/nodejs/node/commit/911cb33cdadab57a75f97186290ea8f3903a6171 (v18.x)
+	NOTE: https://github.com/nodejs/node/commit/911cb33cdadab57a75f97186290ea8f3903a6171 (main)
 CVE-2024-21892 (On Linux, Node.js ignores certain environment variables if those may h ...)
 	- nodejs 18.19.1+dfsg-1 (bug #1064055)
 	[bullseye] - nodejs <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0186c26064ccac35d12224b3caea68435d493d96

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0186c26064ccac35d12224b3caea68435d493d96
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240223/bf8513d9/attachment.htm>


More information about the debian-security-tracker-commits mailing list