package/nodejs: security bump to version 12.22.6
authorPeter Korsgaard <peter@korsgaard.com>
Sat, 18 Sep 2021 16:11:30 +0000 (18:11 +0200)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 18 Sep 2021 17:42:46 +0000 (19:42 +0200)
commite3bdcdd596f916458f86aafc628608ba977d953f
tree4e3ec210e9c36843f3a07189192fcccd00515de3
parentedb6d5f00b3563a8987a5d424f9149b39ce5eaf9
package/nodejs: security bump to version 12.22.6

Fixes the following security issues:

- CVE-2021-37701: Arbitrary File Creation/Overwrite via insufficient symlink
  protection due to directory cache poisoning using symbolic links

- CVE-2021-37712: Arbitrary File Creation/Overwrite via insufficient symlink
  protection due to directory cache poisoning using symbolic links

- CVE-2021-37713: Arbitrary File Creation/Overwrite on Windows via
  insufficient relative path sanitization

- CVE-2021-39134: UNIX Symbolic Link (Symlink) Following in @npmcli/arborist

- CVE-2021-39135: UNIX Symbolic Link (Symlink) Following in @npmcli/arborist

For more details, see the advisory:
https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases2/

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/nodejs/nodejs.hash
package/nodejs/nodejs.mk