Skip to content

v10.24.1 proposal

Rodrigo Muino Tomonari requested to merge v10.24.1-proposal into v10.x

2021-04-06, Version 10.24.1 'Dubnium' (LTS), @mylesborins

This is a security release

Notable Changes

Vulerabilties fixed:

  • CVE-2021-3450: OpenSSL - CA certificate check bypass with X509_V_FLAG_X509_STRICT (High)
  • CVE-2021-3449: OpenSSL - NULL pointer deref in signature_algorithms processing (High)
  • CVE-2020-7774: npm upgrade - Update y18n to fix Prototype-Pollution (High)

Commits

Merge request reports

Loading