nixpkgs/pkgs
Mario Rodas 12bbce3e6c nodejs_20: 20.3.0 -> 20.3.1
The following CVEs are fixed in this release:
- CVE-2023-30581: mainModule.__proto__ Bypass Experimental Policy Mechanism (High)
- CVE-2023-30584: Path Traversal Bypass in Experimental Permission Model (High)
- CVE-2023-30587: Bypass of Experimental Permission Model via Node.js Inspector (High)
- CVE-2023-30582: Inadequate Permission Model Allows Unauthorized File Watching (Medium)
- CVE-2023-30583: Bypass of Experimental Permission Model via fs.openAsBlob() (Medium)
- CVE-2023-30585: Privilege escalation via Malicious Registry Key manipulation during Node.js installer repair process (Medium)
- CVE-2023-30586: Bypass of Experimental Permission Model via Arbitrary OpenSSL Engines (Medium)
- CVE-2023-30588: Process interuption due to invalid Public Key information in x509 certificates (Medium)
- CVE-2023-30589: HTTP Request Smuggling via Empty headers separated by CR (Medium)
- CVE-2023-30590: DiffieHellman does not generate keys after setting a private key (Medium)

https://github.com/nodejs/node/releases/tag/v20.3.1
2023-06-21 04:20:00 +00:00
..
applications terraform-providers.google-beta: 4.69.1 -> 4.70.0 2023-06-21 14:57:01 +10:00
build-support buildDotnetGlobalTool: init 2023-06-20 17:20:52 +02:00
common-updater
data fluent-gtk-theme: 2022-12-15 -> 2023-06-20 2023-06-20 17:20:11 -03:00
desktops plasma-workspace: refresh patch 2023-06-20 19:45:18 +03:00
development nodejs_20: 20.3.0 -> 20.3.1 2023-06-21 04:20:00 +00:00
games Merge pull request #238817 from Kranzes/xonotic 2023-06-21 00:50:01 +03:00
misc
os-specific Merge pull request #238743 from gilice/firmware-updater-06-20 2023-06-20 20:42:12 -06:00
pkgs-lib
servers keycloak.plugins: update mvnHash (#238834) 2023-06-21 07:05:46 +03:00
shells
stdenv
test cudaPackages: bump default cudaPackages_11_7 -> cudaPackages_11_8 (#238622) 2023-06-20 14:12:54 -04:00
tools Merge pull request #238838 from trofi/grim-update 2023-06-21 08:00:15 +03:00
top-level Merge pull request #238503 from Misaka13514/init-fscan 2023-06-21 06:33:35 +02:00