Now
MAIN commitmail json YAML
pkgsrc/lang/nodejs18/Makefile@1.27
/
diff
pkgsrc/lang/nodejs18/PLIST@1.6 / diff
pkgsrc/lang/nodejs18/distinfo@1.16 / diff
pkgsrc/lang/nodejs18/PLIST@1.6 / diff
pkgsrc/lang/nodejs18/distinfo@1.16 / diff
nodejs18: updated to 18.19.1
Version 18.19.1 'Hydrogen' (LTS)
Notable changes
CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
undici version 5.28.3
npm version 10.2.4
Version 18.19.1 'Hydrogen' (LTS)
Notable changes
CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
undici version 5.28.3
npm version 10.2.4