ea-nodejs20 (20.12.1-1+1.1.cpanel) stable; urgency=low

  * EA-12068: Update ea-nodejs20 from v20.12.0 to v20.12.1
  * CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High)
  * CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium)

 -- Cory McIntire <cory@cpanel.net>  Wed, 03 Apr 2024 00:00:00 -0000

ea-nodejs20 (20.12.0-1) stable; urgency=low

  * EA-12050: Update ea-nodejs20 from v20.11.1 to v20.12.0

 -- Cory McIntire <cory@cpanel.net>  Tue, 26 Mar 2024 00:00:00 -0000

ea-nodejs20 (20.11.1-1) stable; urgency=low

  * EA-11975: Update ea-nodejs20 from v20.11.0 to v20.11.1
  * CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  * CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  * CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
  * CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
  * CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  * CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
  * CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
  * CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)

 -- Cory McIntire <cory@cpanel.net>  Wed, 14 Feb 2024 00:00:00 -0000

ea-nodejs20 (20.11.0-1) stable; urgency=low

  * EA-11904: Update ea-nodejs20 from v20.10.0 to v20.11.0

 -- Cory McIntire <cory@cpanel.net>  Wed, 10 Jan 2024 00:00:00 -0000

ea-nodejs20 (20.10.0-1) stable; urgency=low

  * EA-11826: Update ea-nodejs20 from v20.9.0 to v20.10.0

 -- Cory McIntire <cory@cpanel.net>  Wed, 29 Nov 2023 00:00:00 -0000

ea-nodejs20 (20.9.0-1) stable; urgency=low

  * EA-11773: Update ea-nodejs20 from v20.8.1 to v20.9.0

 -- Cory McIntire <cory@cpanel.net>  Thu, 26 Oct 2023 00:00:00 -0000

ea-nodejs20 (20.8.1-1) stable; urgency=low

  * EA-11747: Update ea-nodejs20 from v20.8.0 to v20.8.1

 -- Cory McIntire <cory@cpanel.net>  Mon, 16 Oct 2023 00:00:00 -0000

ea-nodejs20 (20.8.0-1) stable; urgency=low

  * EA-11715: Update ea-nodejs20 from v20.7.0 to v20.8.0
  undici - Cookie headers are not cleared in cross-domain redirect in undici-fetch (High) - (CVE-2023-45143)
  nghttp2 - HTTP/2 Rapid Reset (High) - (CVE-2023-44487)
  Permission model improperly protects against path traversal (High) - (CVE-2023-39331)
  Path traversal through path stored in Uint8Array (High) - (CVE-2023-39332)
  Integrity checks according to policies can be circumvented (Medium) - (CVE-2023-38552)
  Code injection via WebAssembly export names (Low) - (CVE-2023-39333)

 -- Cory McIntire <cory@cpanel.net>  Mon, 02 Oct 2023 00:00:00 -0000

ea-nodejs20 (20.7.0-1) stable; urgency=low

  * EA-11698: Update ea-nodejs20 from v20.6.1 to v20.7.0

 -- Travis Holloway <t.holloway@cpanel.net>  Wed, 20 Sep 2023 00:00:00 -0000

ea-nodejs20 (20.6.1-1) stable; urgency=low

  * EA-11684: Update ea-nodejs20 from v20.6.0 to v20.6.1

 -- Cory McIntire <cory@cpanel.net>  Fri, 15 Sep 2023 00:00:00 -0000

ea-nodejs20 (20.6.0-1) stable; urgency=low

  * EA-11663: Update ea-nodejs20 from v20.5.1 to v20.6.0

 -- Cory McIntire <cory@cpanel.net>  Fri, 08 Sep 2023 00:00:00 -0000

ea-nodejs20 (20.5.1-1) stable; urgency=low

  * ZC-11127: Initial build

 -- Julian Brown <julian.brown@cpanel.net>  Tue, 15 Aug 2023 00:00:00 -0000

