diff --git a/CHANGELOG.md b/CHANGELOG.md index 8ca85315f3ffef..46da45d16d1559 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -86,7 +86,8 @@ release. 20.0.0
-18.20.3
+18.20.4
+18.20.3
18.20.2
18.20.1
18.20.0
diff --git a/doc/changelogs/CHANGELOG_V18.md b/doc/changelogs/CHANGELOG_V18.md index 163004dbeb9d61..54bb13b6e2fe0e 100644 --- a/doc/changelogs/CHANGELOG_V18.md +++ b/doc/changelogs/CHANGELOG_V18.md @@ -9,6 +9,7 @@ +18.20.4
18.20.3
18.20.2
18.20.1
@@ -72,6 +73,22 @@ * [io.js](CHANGELOG_IOJS.md) * [Archive](CHANGELOG_ARCHIVE.md) + + +## 2024-07-08, Version 18.20.4 'Hydrogen' (LTS), @RafaelGSS + +This is a security release. + +### Notable Changes + +* CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980 (High) +* CVE-2024-22020 - Bypass network import restriction via data URL (Medium) + +### Commits + +* \[[`85abedf1ff`](https://github.com/nodejs/node/commit/85abedf1ff)] - **lib,esm**: handle bypass network-import via data: (RafaelGSS) [nodejs-private/node-private#522](https://github.com/nodejs-private/node-private/pull/522) +* \[[`eccd63b865`](https://github.com/nodejs/node/commit/eccd63b865)] - **src**: handle permissive extension on cmd check (RafaelGSS) [nodejs-private/node-private#596](https://github.com/nodejs-private/node-private/pull/596) + ## 2024-05-21, Version 18.20.3 'Hydrogen' (LTS), @richardlau