Логотип exploitDog
bind:CVE-2025-23090
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-23090

Количество 4

Количество 4

ubuntu логотип

CVE-2025-23090

10 месяцев назад

Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.

EPSS: Низкий
nvd логотип

CVE-2025-23090

10 месяцев назад

Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.

EPSS: Низкий
msrc логотип

CVE-2025-23090

2 месяца назад

Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.

EPSS: Низкий
github логотип

GHSA-5vvm-wqc8-r5m8

10 месяцев назад

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-23090

Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.

10 месяцев назад
nvd логотип
CVE-2025-23090

Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.

10 месяцев назад
msrc логотип
CVE-2025-23090

Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2025-23083.

2 месяца назад
github логотип
GHSA-5vvm-wqc8-r5m8

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.

CVSS3: 7.7
10 месяцев назад

Уязвимостей на страницу