|
11 | 11 | </tr>
|
12 | 12 | <tr>
|
13 | 13 | <td valign="top">
|
| 14 | +<a href="#14.17.6">14.17.6</a><br/> |
14 | 15 | <a href="#14.17.5">14.17.5</a><br/>
|
15 | 16 | <a href="#14.17.4">14.17.4</a><br/>
|
16 | 17 | <a href="#14.17.3">14.17.3</a><br/>
|
|
64 | 65 | * [io.js](CHANGELOG_IOJS.md)
|
65 | 66 | * [Archive](CHANGELOG_ARCHIVE.md)
|
66 | 67 |
|
| 68 | +<a id="14.17.6"></a> |
| 69 | +## 2021-08-31, Version 14.17.6 'Fermium' (LTS), @MylesBorins |
| 70 | + |
| 71 | +This is a security release. |
| 72 | + |
| 73 | +### Notable Changes |
| 74 | + |
| 75 | +These are vulnerabilities in the node-tar, arborist, and npm cli modules which |
| 76 | +are related to the initial reports and subsequent remediation of node-tar |
| 77 | +vulnerabilities [CVE-2021-32803](https://github.com/advisories/GHSA-r628-mhmh-qjhw) |
| 78 | +and [CVE-2021-32804](https://github.com/advisories/GHSA-3jfq-g458-7qm9). |
| 79 | +Subsequent internal security review of node-tar and additional external bounty |
| 80 | +reports have resulted in another 5 CVE being remediated in core npm CLI |
| 81 | +dependencies including node-tar, and npm arborist. |
| 82 | + |
| 83 | +You can read more about it in: |
| 84 | + |
| 85 | +* [CVE-2021-37701](https://github.com/npm/node-tar/security/advisories/GHSA-9r2w-394v-53qc) |
| 86 | +* [CVE-2021-37712](https://github.com/npm/node-tar/security/advisories/GHSA-qq89-hq3f-393p) |
| 87 | +* [CVE-2021-37713](https://github.com/npm/node-tar/security/advisories/GHSA-5955-9wpr-37jh) |
| 88 | +* [CVE-2021-39134](https://github.com/npm/arborist/security/advisories/GHSA-2h3h-q99f-3fhc) |
| 89 | +* [CVE-2021-39135](https://github.com/npm/arborist/security/advisories/GHSA-gmw6-94gg-2rc2) |
| 90 | + |
| 91 | +### Commits |
| 92 | + |
| 93 | +* [[`5b3f70bfb5`](https://github.com/nodejs/node/commit/5b3f70bfb5)] - **deps**: update archs files for OpenSSL-1.1.1l (Richard Lau) [#39868](https://github.com/nodejs/node/pull/39868) |
| 94 | +* [[`71372625ae`](https://github.com/nodejs/node/commit/71372625ae)] - **deps**: upgrade openssl sources to 1.1.1l (Richard Lau) [#39868](https://github.com/nodejs/node/pull/39868) |
| 95 | +* [[`4276984803`](https://github.com/nodejs/node/commit/4276984803)] - **deps**: upgrade npm to 6.14.15 (Darcy Clarke) [#39856](https://github.com/nodejs/node/pull/39856) |
| 96 | + |
67 | 97 | <a id="14.17.5"></a>
|
68 | 98 | ## 2021-08-11, Version 14.17.5 'Fermium' (LTS), @BethGriggs
|
69 | 99 |
|
|
0 commit comments