Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 781704 (CVE-2020-7774) - <net-libs/nodejs-{12.22.1,14.16.1,15.14.0}: multiple vulnerabilities
Summary: <net-libs/nodejs-{12.22.1,14.16.1,15.14.0}: multiple vulnerabilities
Status: IN_PROGRESS
Alias: CVE-2020-7774
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://nodejs.org/en/blog/vulnerabil...
Whiteboard: B3 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-04-09 06:48 UTC by Thomas Stein
Modified: 2023-12-24 10:14 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Stein 2021-04-09 06:48:52 UTC
Hello Devs.

Nodejs needs some version bumps. 

cheers, t.

Reproducible: Always
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-04-09 22:47:45 UTC
Thanks! It seems like the first two CVEs have been handled in bug 777681 in the default configuration of nodejs due to system-ssl, and I'm not sure what the impact of the third CVE the vulnerability is in an npm module.
Comment 2 Larry the Git Cow gentoo-dev 2021-04-16 18:25:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6e708b88a117f819f607b3c48a463532fd5f5837

commit 6e708b88a117f819f607b3c48a463532fd5f5837
Author:     Marek Szuba <marecki@gentoo.org>
AuthorDate: 2021-04-16 15:52:39 +0000
Commit:     Marek Szuba <marecki@gentoo.org>
CommitDate: 2021-04-16 18:24:25 +0000

    net-libs/nodejs: bump v14 to 14.16.1
    
    Addresses CVE-2021-3450, CVE-2021-3449 and CVE-2020-7774.
    
    Bug: https://bugs.gentoo.org/781704
    Signed-off-by: Marek Szuba <marecki@gentoo.org>

 net-libs/nodejs/Manifest              |   1 +
 net-libs/nodejs/nodejs-14.16.1.ebuild | 209 ++++++++++++++++++++++++++++++++++
 2 files changed, 210 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5e41eaca605e84e0f641f09f1f5c4ac1826e1e28

commit 5e41eaca605e84e0f641f09f1f5c4ac1826e1e28
Author:     Marek Szuba <marecki@gentoo.org>
AuthorDate: 2021-04-16 15:51:36 +0000
Commit:     Marek Szuba <marecki@gentoo.org>
CommitDate: 2021-04-16 18:24:21 +0000

    net-libs/nodejs: bump v12 to 12.22.1
    
    Addresses CVE-2021-3450, CVE-2021-3449 and CVE-2020-7774.
    
    Bug: https://bugs.gentoo.org/781704
    Signed-off-by: Marek Szuba <marecki@gentoo.org>

 net-libs/nodejs/Manifest              |   1 +
 net-libs/nodejs/nodejs-12.22.1.ebuild | 220 ++++++++++++++++++++++++++++++++++
 2 files changed, 221 insertions(+)
Comment 3 Larry the Git Cow gentoo-dev 2021-04-16 20:40:10 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=01262550fb3abf1b3b37892dc39b376bd73ec906

commit 01262550fb3abf1b3b37892dc39b376bd73ec906
Author:     Marek Szuba <marecki@gentoo.org>
AuthorDate: 2021-04-16 20:36:36 +0000
Commit:     Marek Szuba <marecki@gentoo.org>
CommitDate: 2021-04-16 20:40:01 +0000

    net-libs/nodejs: bump v15 to 15.14.0
    
    Addresses CVE-2021-3450, CVE-2021-3449 and CVE-2020-7774.
    
    Bug: https://bugs.gentoo.org/781704
    Signed-off-by: Marek Szuba <marecki@gentoo.org>

 net-libs/nodejs/Manifest                                         | 2 +-
 net-libs/nodejs/{nodejs-15.11.0.ebuild => nodejs-15.14.0.ebuild} | 4 ++--
 2 files changed, 3 insertions(+), 3 deletions(-)
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-18 01:44:18 UTC
amd64 done
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-18 01:48:13 UTC
arm64 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-18 01:52:35 UTC
ppc64 done
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-19 04:32:28 UTC
arm done
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-22 02:57:36 UTC
x86 done

all arches done
Comment 9 Larry the Git Cow gentoo-dev 2021-04-22 11:52:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=00c00335eeca35c91062475642d308e222dab330

commit 00c00335eeca35c91062475642d308e222dab330
Author:     Marek Szuba <marecki@gentoo.org>
AuthorDate: 2021-04-22 11:45:21 +0000
Commit:     Marek Szuba <marecki@gentoo.org>
CommitDate: 2021-04-22 11:50:15 +0000

    net-libs/nodejs: remove old
    
    No versions vulnerable to CVE-2021-3450, CVE-2021-3449 and CVE-2020-7774
    left in the tree.
    
    Bug: https://bugs.gentoo.org/781704
    Signed-off-by: Marek Szuba <marecki@gentoo.org>

 net-libs/nodejs/Manifest              |   2 -
 net-libs/nodejs/nodejs-12.21.0.ebuild | 220 ----------------------------------
 net-libs/nodejs/nodejs-14.16.0.ebuild | 209 --------------------------------
 3 files changed, 431 deletions(-)
Comment 10 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-04-22 13:11:29 UTC
Thanks!
Comment 11 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-11 03:07:54 UTC
GLSA request filed.
Comment 12 NATTkA bot gentoo-dev 2021-07-30 13:08:35 UTC
Resetting sanity check; package list is empty or all packages are done.