MGASA-2024-0046
Advisory lineage Upstream: 4 Downstream: 0
Published: 22 Feb 2024, 22:20
Last modified:16 Apr 2026, 04:23
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
22 Feb 2024, 22:20
Published
Vulnerability first disclosed
16 Apr 2026, 04:23
Last Modified
Vulnerability information updated
Description
Updated nodejs yarnpkg packages fix security vulnerabilities This is a security release. The following CVEs are fixed in this release: CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High) CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High) CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium) CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium) More detailed information on each of the vulnerabilities can be found in february 2024 Security Releases blog post.
Affected Systems
- mageia•nodejs
< 18.19.1-1.mga9
- mageia•yarnpkg
< 1.22.21-0.10.2.4.1.mga9
References (7)
- https://advisories.mageia.org/MGASA-2024-0046.html
- https://bugs.mageia.org/show_bug.cgi?id=32861
- https://github.com/nodejs/node/releases/tag/v18.19.1
- https://github.com/nodejs/node/releases/tag/v18.19.0
- https://github.com/yarnpkg/yarn/releases/tag/v1.22.21
- https://github.com/yarnpkg/yarn/releases/tag/v1.22.20
- https://nodejs.org/en/blog/vulnerability/february-2024-security-releases