node: bump to v14.21.3 20526/head
authorHirokazu MORIKAWA <morikw2@gmail.com>
Sun, 19 Feb 2023 06:07:45 +0000 (15:07 +0900)
committerHirokazu MORIKAWA <morikw2@gmail.com>
Sun, 19 Feb 2023 06:07:45 +0000 (15:07 +0900)
commitd57b35fa834b1ae80ad29d1c7135d38426ca8265
tree5985a17b5441756573067fa209fcd971070e9eab
parentee193dffb480080eb008c9ad52bd8d1b8ee91bc7
node: bump to v14.21.3

Thursday February 16 2023 Security Releases

Notable Changes
The following CVEs are fixed in this release:
* CVE-2023-23918: Node.js Permissions policies can be bypassed via process.mainModule (High)
* CVE-2023-23920: Node.js insecure loading of ICU data through ICU_DATA environment variable (Low)
More detailed information on each of the vulnerabilities can be found in February 2023 Security Releases blog post.

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
lang/node/Makefile
lang/node/patches/003-path.patch