The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module.
This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x.
Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.
References
Configurations
History
22 Aug 2023, 17:41
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBOZE2QZIBLFFTYWYN23FGKN6HULZ6HX/ - Mailing List | |
References | (MISC) https://hackerone.com/reports/2043807 - Issue Tracking | |
References | (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQPELKG2LVTADSB7ME73AV4DXQK47PWK/ - Mailing List | |
CPE | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
19 Aug 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Aug 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Aug 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-15 16:15
Updated : 2024-02-05 00:01
NVD link : CVE-2023-32006
Mitre link : CVE-2023-32006
CVE.ORG link : CVE-2023-32006
JSON object : View
Products Affected
nodejs
- node.js
fedoraproject
- fedora
CWE