Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc52-gwm3-8v2f

Опубликовано: 31 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Missing "--allow-net" permission check for built-in Node modules

Impact

Outbound HTTP requests made using the built-in "node:http" or "node:https" modules are incorrectly not checked against the network permission allow list (--allow-net). Dependencies relying on these built-in modules are subject to the vulnerability too.

Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected.

Patches

This problem has been patched in Deno v1.34.1 and all users are recommended to update to this version.

Workarounds

No workaround is available for this issue.

Пакеты

Наименование

deno

rust
Затронутые версииВерсия исправления

= 1.34.0

1.34.1

Наименование

deno_runtime

rust
Затронутые версииВерсия исправления

= 0.114.0

0.115.0

EPSS

Процентиль: 34%
0.00141
Низкий

8.6 High

CVSS3

Дефекты

CWE-269
CWE-276

Связанные уязвимости

CVSS3: 8.6
nvd
больше 2 лет назад

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too. Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected. This problem has been patched in Deno v1.34.1 and deno_runtime 0.114.1 and all users are recommended to update to this version. No workaround is available for this issue.

EPSS

Процентиль: 34%
0.00141
Низкий

8.6 High

CVSS3

Дефекты

CWE-269
CWE-276