Bug 31445 - nodejs-minimist new security issue CVE-2021-44906
Summary: nodejs-minimist new security issue CVE-2021-44906
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-01-23 17:10 CET by David Walser
Modified: 2023-02-07 01:08 CET (History)
5 users (show)

See Also:
Source RPM: nodejs-minimist-1.2.5-1.mga8.src.rpm
CVE: CVE-2021-44906
Status comment:


Attachments

Description David Walser 2023-01-23 17:10:10 CET
RedHat has issued an advisory today (January 23):
https://access.redhat.com/errata/RHSA-2023:0321

The issue is fixed upstream in 1.2.6.

Mageia 8 is also affected.
David Walser 2023-01-23 17:10:21 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 1.2.6

Comment 1 Lewis Smith 2023-01-23 19:42:03 CET
This is something hardly touched (the current version is 2y old), no evident packager, so assigning globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2023-01-30 10:25:28 CET
Suggested advisory:
========================

The updated package fixes a security vulnerability:

Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). (CVE-2021-44906)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44906
https://access.redhat.com/errata/RHSA-2023:0321
========================

Updated package in core/updates_testing:
========================
nodejs-minimist-1.2.7-1.mga8

from SRPM:
nodejs-minimist-1.2.7-1.mga8.src.rpm

Status comment: Fixed upstream in 1.2.6 => (none)
CC: (none) => nicolas.salguero
Whiteboard: MGA8TOO => (none)
Source RPM: nodejs-minimist-1.2.5-2.mga9.src.rpm => nodejs-minimist-1.2.5-1.mga8.src.rpm
Version: Cauldron => 8
CVE: (none) => CVE-2021-44906
Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs

Comment 3 Herman Viaene 2023-01-31 15:09:59 CET
MGA8-64 MATE on Aver Aspire 5253
No installation issues
No wiki, no previous updates, so googled a little to find out what this is. Turms out to be a Javascript library, so I give the OK on clean install as with other developer's stuff.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2023-01-31 16:51:24 CET
Validating. Advisory in Comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-02-06 21:18:41 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 5 Mageia Robot 2023-02-07 01:08:47 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0035.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.