March 10, 2021 By Raymond Xu < 1 min read

The SDK-for-Node.js buildpack includes the community January/February 2021 security releases and updated Node.js runtimes.

The January 2021 security release includes fixes for the following: 

  • Use-after-free in TLSWrap (High) (CVE-2020-8265), which impacts all 10.x, 12.x, and 14.x runtimes.
  • HTTP Request Smuggling in nodejs (Low) (CVE-2020-8287), which impacts all 10.x, 12.x, and 14.x runtimes.
  • OpenSSL – EDIPARTYNAME NULL pointer de-reference (CVE-2020-1971), which affects all 10.x, 12.x, and 14.x runtimes.

The February 2021 security release includes fixes for the following: 

  • HTTP2 ‘unknownProtocol’ cause Denial of Service by resource exhaustion (Critical) (CVE-2021-22883), which impacts all 10.x, 12.x, and 14.x runtimes.
  • DNS rebinding in –inspect (CVE-2021-22884), which impacts all 10.x, 12.x, and 14.x runtimes.
  • OpenSSL – Integer overflow in CipherUpdate (CVE-2021-23840), which impacts all 10.x, 12.x, and 14.x runtimes. 

This buildpack contains the following Node.js runtimes: v10.23.3, v10.24.0, v12.20.2, v12.21.0, v14.15.5, v14.16.0. It is based on the community Node.js buildpack v1.7.44. The latest v10 runtime is the default runtime when one is not specified in the package.json. An existing application will not be affected by the new buildpack until you redeploy or restage. New applications will automatically use the new buildpack.

Learn more

More from Cloud

Field programmable gate arrays (FPGAs) vs. microcontrollers: What’s the difference?

6 min read - Field programmable gate arrays (FPGAs) and microcontroller units (MCUs) are two types of commonly compared integrated circuits (ICs) that are typically used in embedded systems and digital design. Both FPGAs and microcontrollers can be thought of as “small computers” that can be integrated into devices and larger systems. As processors, the primary difference between FPGAs and microcontrollers comes down to programmability and processing capabilities. While FPGAs are more powerful and more versatile, they are also more expensive. Microcontrollers are less…

Types of central processing units (CPUs)

8 min read - What is a CPU? The central processing unit (CPU) is the computer’s brain. It handles the assignment and processing of tasks and manages operational functions that all types of computers use. CPU types are designated according to the kind of chip that they use for processing data. There’s a wide variety of processors and microprocessors available, with new powerhouse processors always in development. The processing power CPUs provide enables computers to engage in multitasking activities. Before discussing the types of…

IBM Cloud Reference Architectures unleashed

2 min read - The ability to onboard workloads to cloud quickly and seamlessly is paramount to accelerate enterprises digital transformation journey. At IBM Cloud, we're thrilled to introduce the IBM Cloud® Reference Architectures designed to empower clients, technical architects, strategists and partners to revolutionize the way businesses harness the power of the cloud. VPC resiliency: Strengthening your foundation Explore the resilience of IBM Cloud Virtual Private Cloud through our comprehensive resources. Dive into our VPC Resiliency white paper, a blueprint for building robust…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters