CVE-2023-23920
Summary
| CVE | CVE-2023-23920 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-23 20:15:00 UTC |
| Updated | 2023-05-03 04:15:00 UTC |
| Description | An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5395-1 nodejs |
DEBIAN |
www.debian.org |
|
| Februray 2023 Node.js Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] [DLA 3344-1] nodejs security update |
MLIST |
lists.debian.org |
|
| Thursday February 16 2023 Security Releases | Node.js |
MISC |
nodejs.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160533 Oracle Enterprise Linux Security Update for nodejs:18 (ELSA-2023-1583)
- 160535 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2023-1582)
- 160547 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2023-1743)
- 160639 Oracle Enterprise Linux Security Update for nodejs:18 (ELSA-2023-2654)
- 160640 Oracle Enterprise Linux Security Update for nodejs and nodejs-nodemon (ELSA-2023-2655)
- 181612 Debian Security Update for nodejs (DLA 3344-1)
- 181767 Debian Security Update for nodejs (DSA 5395-1)
- 200161 Ubuntu Security Notification for Node.js Vulnerabilities (USN-6672-1)
- 241304 Red Hat Update for nodejs:14 security (RHSA-2023:1533)
- 241307 Red Hat Update for nodejs:18 security (RHSA-2023:1583)
- 241332 Red Hat Update for nodejs:16 security (RHSA-2023:1582)
- 241341 Red Hat Update for nodejs:14 security (RHSA-2023:1742)
- 241342 Red Hat Update for nodejs:14 security (RHSA-2023:1743)
- 241343 Red Hat Update for rh-nodejs14-nodejs security (RHSA-2023:1744)
- 241429 Red Hat Update for nodejs and nodejs-nodemon security (RHSA-2023:2655)
- 241457 Red Hat Update for nodejs:18 security (RHSA-2023:2654)
- 242132 Red Hat Update for nodejs security (RHSA-2023:5533)
- 284203 Fedora Security Update for nodejs16 (FEDORA-2023-973319d5b7)
- 356918 Amazon Linux Security Advisory for nodejs : ALAS2023-2023-210
- 378467 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2023:0037)
- 502669 Alpine Linux Security Update for nodejs
- 502670 Alpine Linux Security Update for nodejs
- 502748 Alpine Linux Security Update for nodejs
- 6000404 Debian Security Update for nodejs (DSA 5589-1)
- 753741 SUSE Enterprise Linux Security Update for nodejs10 (SUSE-SU-2023:0606-1)
- 753755 SUSE Enterprise Linux Security Update for nodejs14 (SUSE-SU-2023:0674-1)
- 753756 SUSE Enterprise Linux Security Update for nodejs16 (SUSE-SU-2023:0673-1)
- 753758 SUSE Enterprise Linux Security Update for nodejs12 (SUSE-SU-2023:0682-1)
- 905631 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (13703)
- 905674 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (13757)
- 906631 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (13703-3)
- 907156 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (13757-1)
- 940976 AlmaLinux Security Update for nodejs:16 (ALSA-2023:1582)
- 940977 AlmaLinux Security Update for nodejs:18 (ALSA-2023:1583)
- 940979 AlmaLinux Security Update for nodejs:14 (ALSA-2023:1743)
- 941013 AlmaLinux Security Update for nodejs and nodejs-nodemon (ALSA-2023:2655)
- 941014 AlmaLinux Security Update for nodejs:18 (ALSA-2023:2654)
- 960893 Rocky Linux Security Update for nodejs:18 (RLSA-2023:1583)
- 960902 Rocky Linux Security Update for nodejs:16 (RLSA-2023:1582)
- 960917 Rocky Linux Security Update for nodejs:14 (RLSA-2023:1743)
- 960937 Rocky Linux Security Update for nodejs and nodejs-nodemon (RLSA-2023:2655)