Bug 1577703 - nodejs-constantinople: Sandbox bypass leading to arbitrary code execution
Summary: nodejs-constantinople: Sandbox bypass leading to arbitrary code execution
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1577704 1577705 1577706
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-05-14 02:54 UTC by Sam Fowler
Modified: 2021-02-17 00:19 UTC (History)
2 users (show)

Fixed In Version: nodejs-constantinople 3.1.1
Clone Of:
Environment:
Last Closed: 2019-06-10 10:22:47 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-05-14 02:54:40 UTC
Versions of constantinople prior to 3.1.1 are vulnerable to a sandbox bypass which can lead to arbitrary code execution.


External Reference:

https://nodesecurity.io/advisories/568


Upstream commit:

https://github.com/pugjs/constantinople/commit/01d409c0d081dfd65223e6b7767c244156d35f7f

Comment 1 Sam Fowler 2018-05-14 02:55:01 UTC
Created nodejs-constantinople tracking bugs for this issue:

Affects: epel-all [bug 1577704]
Affects: fedora-all [bug 1577705]


Note You need to log in before you can comment on or make changes to this bug.