Opened 4 weeks ago

Closed 3 weeks ago

#19552 closed enhancement (fixed)

node.js-20.12.1

Reported by: Bruce Dubbs Owned by: Rahul Chandra
Priority: elevated Milestone: 12.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version,

Change History (4)

comment:1 by Rahul Chandra, 4 weeks ago

Owner: changed from blfs-book to Rahul Chandra
Status: newassigned

comment:2 by Douglas R. Reno, 3 weeks ago

Priority: normalelevated
Summary: node.js-20.12.0node.js-20.12.1

Now 20.12.1, with two security fixes

comment:3 by Rahul Chandra, 3 weeks ago

Notable Changes

CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High) CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium) llhttp version 9.2.1 undici version 5.28.4

Commits

[bd8f10a257] - deps: update undici to v5.28.4 (Matteo Collina) nodejs-private/node-private#576 [5e34540a96] - http: do not allow OBS fold in headers by default (Paolo Insogna) nodejs-private/node-private#557 [ba1ae6d188] - src: ensure to close stream when destroying session (Anna Henningsen) nodejs-private/node-private#561

comment:4 by Rahul Chandra, 3 weeks ago

Resolution: fixed
Status: assignedclosed
Fixed @
2a406a80d09225e7b9f316a1dcfe0dd881d0e74c - Update to node.js-20.12.1
995d8944b59459835ce51e65dfd10573c3a7ad75 - Update to samba-4.20.0
b759af786bac343cff0d53b398c18eacdbbd0c72 - Update to mesa-24.0.4
Note: See TracTickets for help on using tickets.