﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
17669	node.js v18.14.1	ken@…	ken@…	"This contains fixes for the following five vulnerabilities, in addition to shipping updated OpenSSL (that part should not affect us since we use system OpenSSL):

CVE-2023-23918: Node.js Permissions policies can be bypassed via
process.mainModule (High)

CVE-2023-23919: Node.js OpenSSL error handling issues in nodejs
crypto library (Medium)

CVE-2023-23936: Fetch API in Node.js did not protect against CRLF
injection in host headers (Medium)

CVE-2023-24807: Regular Expression Denial of Service in Headers in
Node.js fetch API (Low)

CVE-2023-23920: Node.js insecure loading of ICU data through
ICU_DATA environment variable (Low)
"	defect	closed	elevated	11.3	BOOK	git	medium	fixed		
