CVE-2023-23918

Name
CVE-2023-23918
Description
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/
CONFIRM https://security.netapp.com/advisory/ntap-20230316-0008/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= 14.0.0 <= 14.14.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= 16.0.0 <= 16.12.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= 18.0.0 <= 18.11.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* nodejs >= 18.0.0 < 18.14.1
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* nodejs >= 16.0.0 < 16.19.1
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= 19.0.0 < 19.6.1
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* nodejs >= 14.0.0 < 14.21.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nodejs edge-main 18.14.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
nodejs edge-main 18.14.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 18.13.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 18.12.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.18.0-r1 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.18.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.17.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.17.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.16.0-r1 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.16.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 16.13.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 14.18.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 14.17.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 14.17.5-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 14.17.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
nodejs edge-main 14.16.1-r0 None possibly vulnerable
nodejs edge-main 14.16.0-r0 None possibly vulnerable
nodejs edge-main 14.15.5-r0 None possibly vulnerable
nodejs edge-main 14.15.4-r0 None possibly vulnerable
nodejs edge-main 14.15.1-r0 None possibly vulnerable
nodejs 3.22-main 18.14.1-r0 None fixed
nodejs 3.22-main 18.12.1-r0 None possibly vulnerable
nodejs 3.22-main 16.17.1-r0 None possibly vulnerable
nodejs 3.22-main 16.13.2-r0 None possibly vulnerable
nodejs 3.22-main 14.18.1-r0 None possibly vulnerable
nodejs 3.22-main 14.17.6-r0 None possibly vulnerable
nodejs 3.22-main 14.17.5-r0 None possibly vulnerable
nodejs 3.22-main 14.17.4-r0 None possibly vulnerable
nodejs 3.22-main 14.16.1-r0 None possibly vulnerable
nodejs 3.22-main 14.16.0-r0 None possibly vulnerable
nodejs 3.22-main 14.15.5-r0 None possibly vulnerable
nodejs 3.22-main 14.15.4-r0 None possibly vulnerable
nodejs 3.22-main 14.15.1-r0 None possibly vulnerable
nodejs 3.21-main 18.14.1-r0 None fixed
nodejs 3.21-main 18.12.1-r0 None possibly vulnerable
nodejs 3.21-main 16.17.1-r0 None possibly vulnerable
nodejs 3.21-main 16.13.2-r0 None possibly vulnerable
nodejs 3.21-main 14.18.1-r0 None possibly vulnerable
nodejs 3.21-main 14.17.6-r0 None possibly vulnerable
nodejs 3.21-main 14.17.5-r0 None possibly vulnerable
nodejs 3.21-main 14.17.4-r0 None possibly vulnerable
nodejs 3.21-main 14.16.1-r0 None possibly vulnerable
nodejs 3.21-main 14.16.0-r0 None possibly vulnerable
nodejs 3.21-main 14.15.5-r0 None possibly vulnerable
nodejs 3.21-main 14.15.4-r0 None possibly vulnerable
nodejs 3.21-main 14.15.1-r0 None possibly vulnerable
nodejs 3.20-main 18.14.1-r0 None fixed
nodejs 3.20-main 18.12.1-r0 None possibly vulnerable
nodejs 3.20-main 16.17.1-r0 None possibly vulnerable
nodejs 3.20-main 16.13.2-r0 None possibly vulnerable
nodejs 3.20-main 14.18.1-r0 None possibly vulnerable
nodejs 3.20-main 14.17.6-r0 None possibly vulnerable
nodejs 3.20-main 14.17.5-r0 None possibly vulnerable
nodejs 3.20-main 14.17.4-r0 None possibly vulnerable
nodejs 3.20-main 14.16.1-r0 None possibly vulnerable
nodejs 3.20-main 14.16.0-r0 None possibly vulnerable
nodejs 3.20-main 14.15.5-r0 None possibly vulnerable
nodejs 3.20-main 14.15.4-r0 None possibly vulnerable
nodejs 3.20-main 14.15.1-r0 None possibly vulnerable
nodejs 3.19-main 18.14.1-r0 None fixed
nodejs 3.19-main 18.12.1-r0 None possibly vulnerable
nodejs 3.19-main 16.17.1-r0 None possibly vulnerable
nodejs 3.19-main 16.13.2-r0 None possibly vulnerable
nodejs 3.19-main 14.18.1-r0 None possibly vulnerable
nodejs 3.19-main 14.17.6-r0 None possibly vulnerable
nodejs 3.19-main 14.17.5-r0 None possibly vulnerable
nodejs 3.19-main 14.17.4-r0 None possibly vulnerable
nodejs 3.19-main 14.16.1-r0 None possibly vulnerable
nodejs 3.19-main 14.16.0-r0 None possibly vulnerable
nodejs 3.19-main 14.15.5-r0 None possibly vulnerable
nodejs 3.19-main 14.15.4-r0 None possibly vulnerable
nodejs 3.19-main 14.15.1-r0 None possibly vulnerable
nodejs 3.18-main 18.14.1-r0 None fixed
nodejs 3.17-main 18.14.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed