Versions of tunnel-agent before 0.6.0 are vulnerable to memory exposure. This is exploitable if user supplied input is provided to the auth value and is a number. External References: https://nodesecurity.io/advisories/598 Upstream commit: https://github.com/request/tunnel-agent/commit/9ca95ec7219daface8a6fc2674000653de0922c0
Created nodejs-tunnel-agent tracking bugs for this issue: Affects: epel-all [bug 1577734] Affects: fedora-all [bug 1577735]
NodeJS is only included as an imagestream in Openshift Enterprise 3.9. The image is being published by RH Software Collections, so we'll pick up a future release when that becomes available.
RHMAP 4.6 uses NodeJS 6 (6-18) image from RH Software Collections for all it's NodeJS images. Because this is a low impact flaw setting to WONTFIX.