Files
meta-openembedded/meta-oe/recipes-devtools
Polampalli, Archana d3ee870fb0 nodejs: fix CVE-2022-25883
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression
Denial of Service (ReDoS) via the function new Range, when untrusted user data is
provided as a range.

References:
https://nvd.nist.gov/vuln/detail/CVE-2022-25883

Upstream patches:
https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2023-09-04 11:59:59 -04:00
..
2023-05-09 06:51:22 -04:00
2021-08-03 10:21:25 -07:00
2023-07-02 11:17:52 -04:00
2021-11-09 20:57:14 -08:00
2021-12-27 11:46:41 -08:00
2022-04-13 19:21:41 -07:00
2023-09-04 11:59:59 -04:00
2022-04-13 19:21:41 -07:00
2023-08-25 10:39:46 -04:00
2022-02-23 09:25:19 -08:00
2021-08-03 10:21:25 -07:00
2021-12-09 08:37:06 -08:00
2022-07-21 07:17:15 -07:00
2021-08-03 10:21:25 -07:00
2021-11-18 11:07:10 -08:00
2023-08-03 16:47:53 -04:00