CVE-2023-23920
4.2
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Exploitability: 0.6 / Impact: 3.6
Source: NVD
Description
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
Affected (8)
Products: Nodejs: Node.js · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (8)
Source: support@hackerone.com
Mailing List
Source: support@hackerone.com
PatchVendor Advisory
Source: support@hackerone.com
Source: support@hackerone.com
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.