Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2022:7044 - Security Advisory
Issued:
2022-10-19
Updated:
2022-10-19

RHSA-2022:7044 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: rh-nodejs14-nodejs security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

  • nodejs: Improper handling of URI Subject Alternative Names (CVE-2021-44531)
  • nodejs: Certificate Verification Bypass via String Injection (CVE-2021-44532)
  • nodejs: Incorrect handling of certificate subject and issuer fields (CVE-2021-44533)
  • minimist: prototype pollution (CVE-2021-44906)
  • nodejs: HTTP Request Smuggling due to incorrect parsing of header fields (CVE-2022-35256)
  • nodejs: Prototype pollution via console.table properties (CVE-2022-21824)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Software Collections (for RHEL Server) 1 for RHEL 7 x86_64
  • Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7 s390x
  • Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7 ppc64le
  • Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7 x86_64

Fixes

  • BZ - 2040839 - CVE-2021-44531 nodejs: Improper handling of URI Subject Alternative Names
  • BZ - 2040846 - CVE-2021-44532 nodejs: Certificate Verification Bypass via String Injection
  • BZ - 2040856 - CVE-2021-44533 nodejs: Incorrect handling of certificate subject and issuer fields
  • BZ - 2040862 - CVE-2022-21824 nodejs: Prototype pollution via console.table properties
  • BZ - 2066009 - CVE-2021-44906 minimist: prototype pollution
  • BZ - 2130518 - CVE-2022-35256 nodejs: HTTP Request Smuggling due to incorrect parsing of header fields

CVEs

  • CVE-2021-44531
  • CVE-2021-44532
  • CVE-2021-44533
  • CVE-2021-44906
  • CVE-2022-21824
  • CVE-2022-35256

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Software Collections (for RHEL Server) 1 for RHEL 7

SRPM
rh-nodejs14-nodejs-14.20.1-2.el7.src.rpm SHA-256: 787053daf16b9cffeb60805a759bb9b67a6eaefaf2e4b974162f3b3c56f661dc
x86_64
rh-nodejs14-nodejs-14.20.1-2.el7.x86_64.rpm SHA-256: 7c725b5b7c8ecbcee1cc692bedcfa0ae0cb27a216972def9121f906a5915dd30
rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.x86_64.rpm SHA-256: c233e239b3ad92a8825eb6dca33f9238c6698ff8a61b7a83add10b43c2bf7d66
rh-nodejs14-nodejs-devel-14.20.1-2.el7.x86_64.rpm SHA-256: 6c52a3401e77dbb4538d00c6c22a75a736ff6248ef712130cf8b6700eaef4ed3
rh-nodejs14-nodejs-docs-14.20.1-2.el7.noarch.rpm SHA-256: f23ee75f17279a2dfb5d741db7d1a6bcac01efaf51738bfcda926bb3193c881a
rh-nodejs14-npm-6.14.17-14.20.1.2.el7.x86_64.rpm SHA-256: 141b18859bf67797e2ff957b3279ff8389797f284e6272eb4bfa646fc5937383

Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7

SRPM
rh-nodejs14-nodejs-14.20.1-2.el7.src.rpm SHA-256: 787053daf16b9cffeb60805a759bb9b67a6eaefaf2e4b974162f3b3c56f661dc
s390x
rh-nodejs14-nodejs-14.20.1-2.el7.s390x.rpm SHA-256: b320b1d6b1467b74397641682af16e4195f742d28f6c49005737d425dfa8d44d
rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.s390x.rpm SHA-256: 4d052b0f540df26f09035ee16e35c8907d17c3b88ce2657eb87d2ab2d4e47052
rh-nodejs14-nodejs-devel-14.20.1-2.el7.s390x.rpm SHA-256: 3ded7a939973b5e86e4831936e51d89c4334fe0f5b162361f3fb6db7eab18cad
rh-nodejs14-nodejs-docs-14.20.1-2.el7.noarch.rpm SHA-256: f23ee75f17279a2dfb5d741db7d1a6bcac01efaf51738bfcda926bb3193c881a
rh-nodejs14-npm-6.14.17-14.20.1.2.el7.s390x.rpm SHA-256: 4596066fdb1cb77436d3504b31cd374039a373ea69f228d51b80d411e939af40

Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7

SRPM
rh-nodejs14-nodejs-14.20.1-2.el7.src.rpm SHA-256: 787053daf16b9cffeb60805a759bb9b67a6eaefaf2e4b974162f3b3c56f661dc
ppc64le
rh-nodejs14-nodejs-14.20.1-2.el7.ppc64le.rpm SHA-256: 09ac08606fd168ebc85a2d3a7584b5c0c374948d51a7082eeec634cf797c9c02
rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.ppc64le.rpm SHA-256: 7c8efbc27c940404ef5cf3b582ccefc4ae0ac44754036819d7ffe0578ef28bfa
rh-nodejs14-nodejs-devel-14.20.1-2.el7.ppc64le.rpm SHA-256: 105c8fd08ad03c9f8a3f29d9a7c277951466c47a0dc4d6ed33bf260fb4a5a585
rh-nodejs14-nodejs-docs-14.20.1-2.el7.noarch.rpm SHA-256: f23ee75f17279a2dfb5d741db7d1a6bcac01efaf51738bfcda926bb3193c881a
rh-nodejs14-npm-6.14.17-14.20.1.2.el7.ppc64le.rpm SHA-256: d37f05e6d69c22e2ac27207c2ee741408c256d874c9d29f637c26dd8871fbdff

Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7

SRPM
rh-nodejs14-nodejs-14.20.1-2.el7.src.rpm SHA-256: 787053daf16b9cffeb60805a759bb9b67a6eaefaf2e4b974162f3b3c56f661dc
x86_64
rh-nodejs14-nodejs-14.20.1-2.el7.x86_64.rpm SHA-256: 7c725b5b7c8ecbcee1cc692bedcfa0ae0cb27a216972def9121f906a5915dd30
rh-nodejs14-nodejs-debuginfo-14.20.1-2.el7.x86_64.rpm SHA-256: c233e239b3ad92a8825eb6dca33f9238c6698ff8a61b7a83add10b43c2bf7d66
rh-nodejs14-nodejs-devel-14.20.1-2.el7.x86_64.rpm SHA-256: 6c52a3401e77dbb4538d00c6c22a75a736ff6248ef712130cf8b6700eaef4ed3
rh-nodejs14-nodejs-docs-14.20.1-2.el7.noarch.rpm SHA-256: f23ee75f17279a2dfb5d741db7d1a6bcac01efaf51738bfcda926bb3193c881a
rh-nodejs14-npm-6.14.17-14.20.1.2.el7.x86_64.rpm SHA-256: 141b18859bf67797e2ff957b3279ff8389797f284e6272eb4bfa646fc5937383

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility