Skip to content

v10.24.1 proposal#38085

Merged
MylesBorins merged 4 commits intov10.xfrom
v10.24.1-proposal
Apr 6, 2021
Merged

v10.24.1 proposal#38085
MylesBorins merged 4 commits intov10.xfrom
v10.24.1-proposal

Conversation

@MylesBorins
Copy link
Contributor

@MylesBorins MylesBorins commented Apr 4, 2021

2021-04-06, Version 10.24.1 'Dubnium' (LTS), @MylesBorins

This is a security release

Notable Changes

Vulerabilties fixed:

  • CVE-2021-3450: OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High)
  • CVE-2021-3449: OpenSSL - NULL pointer deref in signature_algorithms processing (High)
  • CVE-2020-7774: npm upgrade - Update y18n to fix Prototype-Pollution (High)
    • This is a vulnerability in the y18n NPM module which may be exploited by prototype pollution. You can read more about it in GHSA-c4w7-xm78-47vh
    • Impacts:
      • All versions of the 14.x, 12.x and 10.x releases lines

Commits

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Issues and PRs related to Node.js releases.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants