皇上,还记得我吗?我就是1999年那个Linux伊甸园啊-----24小时滚动更新开源资讯,全年无休!

Node v12.18.4 (LTS) , Node v14.11.0 (Current) , Node v10.22.1 (LTS) 释出

15 Sep September 2020 Security Releases

Updates are now available for v10,x, v12.x and v14.x Node.js release lines for the following issues.

Affected Node.js versions converted carriage returns in HTTP request headers to a hyphen before parsing. This can lead to HTTP Request Smuggling as it is a non-standard interpretation of the header.

Read more…

Node v12.18.4 (LTS)

This is a security release.

Vulnerabilities fixed:

  • CVE-2020-8201: HTTP Request Smuggling due to CR-to-Hyphen conversion (High).
  • CVE-2020-8252: fs.realpath.native on may cause buffer overflow (Medium).

Read more…

Node v14.11.0 (Current)

This is a security release.

Vulnerabilities fixed:

  • CVE-2020-8251: Denial of Service by resource exhaustion CWE-400 due to unfinished HTTP/1.1 requests (Critical).
  • CVE-2020-8201: HTTP Request Smuggling due to CR-to-Hyphen conversion (High).

Read more…

Node v10.22.1 (LTS)

This is a security release.

Vulnerabilities fixed:

  • CVE-2020-8252: fs.realpath.native on may cause buffer overflow (Medium).

Read more…

转自 https://nodejs.org/en/blog/