Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr4q-vx84-9g5x

Опубликовано: 19 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

EPSS

Процентиль: 60%
0.00403
Низкий

7.3 High

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 1 года назад

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

CVSS3: 7.3
redhat
больше 1 года назад

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

CVSS3: 7.3
nvd
больше 1 года назад

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

CVSS3: 7.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.3
debian
больше 1 года назад

setuid() does not affect libuv's internal io_uring operations if initi ...

EPSS

Процентиль: 60%
0.00403
Низкий

7.3 High

CVSS3

Дефекты

CWE-250