diff options
author | Beth Griggs <Bethany.Griggs@uk.ibm.com> | 2020-02-05 00:44:37 +0000 |
---|---|---|
committer | Beth Griggs <Bethany.Griggs@uk.ibm.com> | 2020-02-05 23:22:07 +0000 |
commit | 5ba7df3c4b81ab695029dacf34a0aa960be71372 (patch) | |
tree | 827a90efae535ad798747945446def254f34611a /doc/osx_installer_logo.png | |
parent | e2c8f89b7572a7aea62927923e425bbd7725dca2 (diff) | |
download | node-new-5ba7df3c4b81ab695029dacf34a0aa960be71372.tar.gz |
2020-02-06, Version 10.19.0 'Dubnium' (LTS)v10.19.0
This is a security release.
Vulnerabilities fixed:
* **CVE-2019-15606**:
HTTP header values do not have trailing OWS trimmed.
* **CVE-2019-15605**:
HTTP request smuggling using malformed Transfer-Encoding header.
* **CVE-2019-15604**:
Remotely trigger an assertion on a TLS server with a malformed
certificate string.
Also, HTTP parsing is more strict to be more secure. Since this may
cause problems in interoperability with some non-conformant HTTP
implementations, it is possible to disable the strict checks with the
`--insecure-http-parser` command line flag, or the `insecureHTTPParser`
http option. Using the insecure HTTP parser should be avoided.
PR-URL: https://github.com/nodejs-private/node-private/pull/198
Diffstat (limited to 'doc/osx_installer_logo.png')
0 files changed, 0 insertions, 0 deletions