Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-38552

Опубликовано: 13 окт. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to node's policy implementation, thus effectively disabling the integrity check.

Отчет

The vulnerability is triggered in an experimental feature that is not widely deployed at the time this vulnerability was disclosed, which is why Red Hat has marked this vulnerability as moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs:16/nodejsWill not fix
Red Hat Enterprise Linux 9nodejsWill not fix
Red Hat Enterprise Linux 9nodejs:20/nodejsAffected
Red Hat Software Collectionsrh-nodejs14-nodejsWill not fix
Red Hat Enterprise Linux 8nodejsFixedRHSA-2023:586918.10.2023
Red Hat Enterprise Linux 8nodejsFixedRHSA-2023:720514.11.2023
Red Hat Enterprise Linux 9nodejsFixedRHSA-2023:584918.10.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=2244415nodejs: integrity checks according to policies can be circumvented

EPSS

Процентиль: 60%
0.00397
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

CVSS3: 7.5
nvd
больше 2 лет назад

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

CVSS3: 7.5
msrc
больше 2 лет назад

When the Node.js policy feature checks the integrity of a resource against a trusted manifest the application can intercept the operation and return a forged checksum to the node's policy implementation thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and 20.x. Please note that at the time this CVE was issued the policy mechanism is an experimental feature of Node.js.

CVSS3: 7.5
debian
больше 2 лет назад

When the Node.js policy feature checks the integrity of a resource aga ...

CVSS3: 7.5
github
больше 2 лет назад

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

EPSS

Процентиль: 60%
0.00397
Низкий

7.5 High

CVSS3