The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module.
This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x.
Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.
References
Configurations
History
15 Sep 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Aug 2023, 17:41
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fedoraproject
Fedoraproject fedora Nodejs node.js Nodejs |
|
References | (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBOZE2QZIBLFFTYWYN23FGKN6HULZ6HX/ - Mailing List | |
References | (MISC) https://hackerone.com/reports/2043807 - Issue Tracking | |
References | (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQPELKG2LVTADSB7ME73AV4DXQK47PWK/ - Mailing List | |
CPE | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | NVD-CWE-noinfo |
19 Aug 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Aug 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Aug 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-15 16:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-32006
Mitre link : CVE-2023-32006
CVE.ORG link : CVE-2023-32006
JSON object : View
Products Affected
fedoraproject
- fedora
nodejs
- node.js
CWE