Skip to content

v14.16.1 proposal#38082

Merged
MylesBorins merged 4 commits intov14.xfrom
v14.16.1-proposal
Apr 6, 2021
Merged

v14.16.1 proposal#38082
MylesBorins merged 4 commits intov14.xfrom
v14.16.1-proposal

Conversation

@MylesBorins
Copy link
Copy Markdown
Contributor

@MylesBorins MylesBorins commented Apr 4, 2021

2021-04-06, Version 14.16.1 'Fermium' (LTS), @MylesBorins

This is a security release.

Notable Changes

Vulnerabilities fixed:

Commits

tniessen and others added 3 commits April 4, 2021 15:31
This updates all sources in deps/openssl/openssl by:
    $ cd deps/openssl/
    $ rm -rf openssl
    $ tar zxf ~/tmp/openssl-1.1.1k.tar.gz
    $ mv openssl-1.1.1k openssl
    $ git add --all openssl
    $ git commit openssl

PR-URL: #37938
Refs: #37913
Refs: #37916
Reviewed-By: Jiawen Geng <[email protected]>
Reviewed-By: Daniel Bevenius <[email protected]>
After an OpenSSL source update, all the config files need to be
regenerated and committed by:
   $ make -C deps/openssl/config
   $ git add deps/openssl/config/archs
   $ git add deps/openssl/openssl/include/crypto/bn_conf.h
   $ git add deps/openssl/openssl/include/crypto/dso_conf.h
   $ git add deps/openssl/openssl/include/openssl/opensslconf.h
   $ git commit

PR-URL: #37938
Refs: #37913
Refs: #37916
Reviewed-By: Jiawen Geng <[email protected]>
Reviewed-By: Daniel Bevenius <[email protected]>
PR-URL: #37918
Reviewed-By: Ruben Bridgewater <[email protected]>
Reviewed-By: Richard Lau <[email protected]>
Reviewed-By: Luigi Pinca <[email protected]>
Reviewed-By: Tobias Nießen <[email protected]>
@nodejs-github-bot nodejs-github-bot added meta Issues and PRs related to the general management of the project. needs-ci PRs that need a full CI run. npm Issues and PRs related to the npm client dependency or the npm registry. v14.x labels Apr 4, 2021
@nodejs-github-bot
Copy link
Copy Markdown
Collaborator

nodejs-github-bot commented Apr 4, 2021

@nodejs nodejs deleted a comment from nodejs-github-bot Apr 5, 2021
MylesBorins added a commit that referenced this pull request Apr 5, 2021
This is a security release.

Notable Changes:

Vulnerabilities fixed:

- **CVE-2021-3450**: OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High)
- **CVE-2021-3449**: OpenSSL - NULL pointer deref in signature_algorithms processing (High)
- **CVE-2020-7774**: npm upgrade - Update y18n to fix Prototype-Pollution (High)

PR-URL: #38082
@nodejs nodejs deleted a comment from nodejs-github-bot Apr 5, 2021
@nodejs-github-bot
Copy link
Copy Markdown
Collaborator

Comment thread doc/changelogs/CHANGELOG_V14.md Outdated
This is a security release.

Notable Changes:

Vulnerabilities fixed:

- **CVE-2021-3450**: OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High)
- **CVE-2021-3449**: OpenSSL - NULL pointer deref in signature_algorithms processing (High)
- **CVE-2020-7774**: npm upgrade - Update y18n to fix Prototype-Pollution (High)

PR-URL: #38082
MylesBorins added a commit that referenced this pull request Apr 6, 2021
@MylesBorins MylesBorins merged commit b34a9d7 into v14.x Apr 6, 2021
MylesBorins added a commit that referenced this pull request Apr 6, 2021
This is a security release.

Notable Changes:

Vulnerabilities fixed:

- **CVE-2021-3450**: OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High)
- **CVE-2021-3449**: OpenSSL - NULL pointer deref in signature_algorithms processing (High)
- **CVE-2020-7774**: npm upgrade - Update y18n to fix Prototype-Pollution (High)

PR-URL: #38082
@MylesBorins MylesBorins deleted the v14.16.1-proposal branch April 6, 2021 20:11
MylesBorins added a commit to nodejs/nodejs.org that referenced this pull request Apr 6, 2021
MylesBorins added a commit to nodejs/nodejs.org that referenced this pull request Apr 6, 2021
@targos targos added the release Issues and PRs related to Node.js releases. label Apr 11, 2021
@targos targos removed needs-ci PRs that need a full CI run. npm Issues and PRs related to the npm client dependency or the npm registry. meta Issues and PRs related to the general management of the project. labels Jun 6, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release Issues and PRs related to Node.js releases.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants