Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-33966

Опубликовано: 31 мая 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 9.8
EPSS Низкий

Описание

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in node:http or node:https modules are incorrectly not checked against the network permission allow list (--allow-net). Dependencies relying on these built-in modules are subject to the vulnerability too. Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected. This problem has been patched in Deno v1.34.1 and deno_runtime 0.114.1 and all users are recommended to update to this version. No workaround is available for this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:deno:deno:1.34.0:*:*:*:*:*:*:*
cpe:2.3:a:deno:deno_runtime:0.114.0:*:*:*:*:rust:*:*

EPSS

Процентиль: 34%
0.00141
Низкий

8.6 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-269
CWE-276

Связанные уязвимости

CVSS3: 8.6
github
больше 2 лет назад

Missing "--allow-net" permission check for built-in Node modules

EPSS

Процентиль: 34%
0.00141
Низкий

8.6 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-269
CWE-276