Описание
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Will not fix | ||
Red Hat Enterprise Linux 8 | nodejs | Not affected | ||
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2023:1582 | 04.04.2023 |
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2023:1583 | 04.04.2023 |
Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2023:1743 | 12.04.2023 |
Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs | Fixed | RHSA-2023:1533 | 30.03.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs | Fixed | RHSA-2023:1742 | 12.04.2023 |
Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2023:2654 | 09.05.2023 |
Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2023:2655 | 09.05.2023 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14 | Fixed | RHSA-2023:1744 | 12.04.2023 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14 ...
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.
7.5 High
CVSS3