File _patchinfo of Package patchinfo.34067
<patchinfo incident="34067">
<issue tracker="cve" id="2024-30260"/>
<issue tracker="cve" id="2024-30261"/>
<issue tracker="bnc" id="1222603">VUL-0: CVE-2024-30261: nodejs: fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect</issue>
<issue tracker="bnc" id="1222530">VUL-0: CVE-2024-30260: nodejs, nodejs-electron: undici: proxy-authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline</issue>
<packager>adamm</packager>
<rating>low</rating>
<category>security</category>
<summary>Security update for nodejs16</summary>
<description>This update for nodejs16 fixes the following issues:
- CVE-2024-30260: undici: proxy-authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline (bsc#1222530)
- CVE-2024-30261: undici: Ensure that integrity cannot be tampered with (bsc#1222603)
</description>
</patchinfo>