Описание
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Fix deferred | ||
| Red Hat Enterprise Linux 8 | nodejs | Not affected | ||
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2023:1582 | 04.04.2023 |
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2023:1583 | 04.04.2023 |
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2023:1743 | 12.04.2023 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs | Fixed | RHSA-2023:1533 | 30.03.2023 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs | Fixed | RHSA-2023:1742 | 12.04.2023 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2023:2654 | 09.05.2023 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2023:2655 | 09.05.2023 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | nodejs | Fixed | RHSA-2023:5533 | 09.10.2023 |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=2172217Node.js: insecure loading of ICU data through ICU_DATA environment variable
4.2 Medium
CVSS3
Связанные уязвимости
CVSS3: 4.2
ubuntu
почти 3 года назад
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
CVSS3: 4.2
nvd
почти 3 года назад
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
CVSS3: 4.2
debian
почти 3 года назад
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18 ...
4.2 Medium
CVSS3