nixpkgs/pkgs/development/web/nodejs
Mario Rodas 12bbce3e6c nodejs_20: 20.3.0 -> 20.3.1
The following CVEs are fixed in this release:
- CVE-2023-30581: mainModule.__proto__ Bypass Experimental Policy Mechanism (High)
- CVE-2023-30584: Path Traversal Bypass in Experimental Permission Model (High)
- CVE-2023-30587: Bypass of Experimental Permission Model via Node.js Inspector (High)
- CVE-2023-30582: Inadequate Permission Model Allows Unauthorized File Watching (Medium)
- CVE-2023-30583: Bypass of Experimental Permission Model via fs.openAsBlob() (Medium)
- CVE-2023-30585: Privilege escalation via Malicious Registry Key manipulation during Node.js installer repair process (Medium)
- CVE-2023-30586: Bypass of Experimental Permission Model via Arbitrary OpenSSL Engines (Medium)
- CVE-2023-30588: Process interuption due to invalid Public Key information in x509 certificates (Medium)
- CVE-2023-30589: HTTP Request Smuggling via Empty headers separated by CR (Medium)
- CVE-2023-30590: DiffieHellman does not generate keys after setting a private key (Medium)

https://github.com/nodejs/node/releases/tag/v20.3.1
2023-06-21 04:20:00 +00:00
..
bypass-darwin-xcrun-node16.patch nodejs: add back newer bypass-xcrun patch 2022-10-01 08:54:20 +09:00
bypass-xcodebuild.diff
disable-darwin-v8-system-instrumentation-node19.patch nodejs-19_x: init at 19.0.0 2022-10-20 04:20:00 +00:00
disable-darwin-v8-system-instrumentation.patch
fix-npm-patch-paths.sh nodejs: add helper patch for buildNpmPackage 2023-05-20 18:29:36 -04:00
node-npm-build-npm-package-logic-node16.patch nodejs_16: add helper patch for buildNpmPackage 2023-05-20 18:29:43 -04:00
node-npm-build-npm-package-logic.patch nodejs: add helper patch for buildNpmPackage 2023-05-20 18:29:36 -04:00
nodejs-release-keys.asc
nodejs.nix nodejs: add -licuuc to libv8 pkg-config file 2023-05-30 09:37:53 +00:00
npm-patches.nix nodejs-{16,18,19}_x: backport npm pack fixes from npm v9 2022-12-13 19:40:27 -05:00
revert-arm64-pointer-auth.patch nodejs-19_x: 19.1.0 -> 19.2.0 2022-11-30 04:20:00 +00:00
setup-hook.sh nodejs: Fix setup-hook addNodePath quoting 2022-03-11 20:00:00 +01:00
update-keyring
update.nix
v14.nix nodejs-14_x: 14.21.2 -> 14.21.3 2023-02-17 04:20:00 +00:00
v16.nix nodejs_16: 16.20.0 -> 16.20.1 2023-06-21 04:20:00 +00:00
v18.nix nodejs_18: 18.16.0 -> 18.16.1 2023-06-21 04:20:00 +00:00
v20.nix nodejs_20: 20.3.0 -> 20.3.1 2023-06-21 04:20:00 +00:00