{"id":"MGASA-2024-0046","summary":"Updated nodejs yarnpkg packages fix security vulnerabilities","details":"This is a security release. The following CVEs are fixed in this\nrelease:\nCVE-2024-21892 - Code injection and privilege escalation through Linux\ncapabilities- (High)\nCVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded\nchunk extension allows DoS attacks- (High)\nCVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing\nvariant of the Bleichenbacher attack against PKCS#1 v1.5 padding) -\n(Medium)\nCVE-2024-22025 - Denial of Service by resource exhaustion in fetch()\nbrotli decoding - (Medium)\nMore detailed information on each of the vulnerabilities can be found in\nfebruary 2024 Security Releases blog post.\n","modified":"2026-04-16T04:44:03.218532009Z","published":"2024-02-22T22:20:27Z","upstream":["CVE-2023-46809","CVE-2024-21892","CVE-2024-22019","CVE-2024-22025"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0046.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32861"},{"type":"WEB","url":"https://github.com/nodejs/node/releases/tag/v18.19.1"},{"type":"WEB","url":"https://github.com/nodejs/node/releases/tag/v18.19.0"},{"type":"WEB","url":"https://github.com/yarnpkg/yarn/releases/tag/v1.22.21"},{"type":"WEB","url":"https://github.com/yarnpkg/yarn/releases/tag/v1.22.20"},{"type":"WEB","url":"https://nodejs.org/en/blog/vulnerability/february-2024-security-releases"}],"affected":[{"package":{"name":"nodejs","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/nodejs?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18.19.1-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0046.json"}},{"package":{"name":"yarnpkg","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/yarnpkg?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.21-0.10.2.4.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0046.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}