Vulnerability
Tuesday February 14 2023 Security Releases
Pre-release announce Summary The Node.js project will release new versions of the 14.x, 16.x, 18.x and 19.x releases lines on or shortly after, Tuesday February 14 2023 in order to address: 2 low severity issues. 2 medium severity issues. 1 high severity issues. OpenSSL security updates for which the highest Read more…
Vulnerability
OpenSSL 3.0.7 update assessment
Summary The vulnerability in the OpenSSL Security Advisory of Dec 13 2022 do not affect any active Node.js release lines. Analysis Our assessment of the security advisory is: X.509 Policy Constraints Double Locking (CVE-2022-3996) Node.js doesn’t call OpenSSL as a separate process (so the possibility to use the 1-policy flag Read more…