node: July 8, 2024 Security Releases
authorHirokazu MORIKAWA <redacted>
Wed, 10 Jul 2024 00:03:49 +0000 (09:03 +0900)
committerTianling Shen <redacted>
Wed, 10 Jul 2024 02:36:48 +0000 (10:36 +0800)
commitebc219db41fc0e52389155dc4e2b5729c19421e2
tree232f8a7ee50ae426f6644d0254124a68043970ea
parent6769d5cf118b3a31ca4ecc36a5d656f50b19d059
node: July 8, 2024 Security Releases

This is a security release.

Notable Changes

    CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980 (High)
    CVE-2024-22020 - Bypass network import restriction via data URL (Medium)
    CVE-2024-22018 - fs.lstat bypasses permission model (Low)
    CVE-2024-36137 - fs.fchown/fchmod bypasses permission model (Low)
    CVE-2024-37372 - Permission model improperly processes UNC paths (Low)

Signed-off-by: Hirokazu MORIKAWA <redacted>
lang/node/Makefile
git clone https://git.99rst.org/PROJECT