Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 924704 (CVE-2023-46809, CVE-2024-21890, CVE-2024-21891, CVE-2024-21892, CVE-2024-21896, CVE-2024-22017, CVE-2024-22019, CVE-2024-22025) - <net-libs/nodejs-{18.19.1,20.11.0}: Multiple vulnerabilities
Summary: <net-libs/nodejs-{18.19.1,20.11.0}: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2023-46809, CVE-2024-21890, CVE-2024-21891, CVE-2024-21892, CVE-2024-21896, CVE-2024-22017, CVE-2024-22019, CVE-2024-22025
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B2 [glsa+]
Keywords:
Depends on: 930080
Blocks:
  Show dependency tree
 
Reported: 2024-02-16 09:53 UTC by m1027
Modified: 2025-05-14 14:45 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description m1027 2024-02-16 09:53:58 UTC
The current nodejs-20.11.0 is said to have a lot of vulnerabilities, being fixed in 20.11.1.

Please add 20.11.1 to portage.

FYI, the nodejs changelog for 20.11.1:

https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V20.md#20.11.1
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-02-17 01:55:14 UTC
commit bff27b8be4bffecfe39c19f17754a5ae7a3c21d2
Author: William Hubbs <williamh@gentoo.org>
Date:   Fri Feb 16 12:39:31 2024 -0600

    net-libs/nodejs: add 18.19.1

    Signed-off-by: William Hubbs <williamh@gentoo.org>

commit 4659eec27a32476ee8d7549d6dcbcb4b7baa5497
Author: William Hubbs <williamh@gentoo.org>
Date:   Fri Feb 16 12:39:31 2024 -0600

    net-libs/nodejs: add 20.11.1

    Signed-off-by: William Hubbs <williamh@gentoo.org>
Comment 2 m1027 2024-02-17 06:21:55 UTC
Thanks!
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-02-18 09:53:11 UTC
Turning it into a security bug (sorry, I meant to do that before, but wanted to post the comment as a reminder for myself...)

CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
Comment 4 m1027 2024-04-18 19:26:41 UTC
FYI: 20.11.1 has recently been removed from portage in favor of 20.12.1. But since 20.12.1 has other isues (BTW: some ssl related) I am forced now to go back to 20.11.0 which has the said vulnearbilities mentioned here... I'd be happy if I had 20.11.1 around for a while.
Comment 5 Larry the Git Cow gentoo-dev 2025-05-14 14:44:51 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=bd1a2640ccf5e62255777408273d6e65a893a6b7

commit bd1a2640ccf5e62255777408273d6e65a893a6b7
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2025-05-14 14:44:20 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2025-05-14 14:44:48 +0000

    [ GLSA 202505-11 ] Node.js: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/916513
    Bug: https://bugs.gentoo.org/924704
    Bug: https://bugs.gentoo.org/928532
    Bug: https://bugs.gentoo.org/936204
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202505-11.xml | 64 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 64 insertions(+)