A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Fri, 25 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nodejs
Nodejs nodejs |
|
CPEs | cpe:2.3:a:nodejs:nodejs:*:*:*:*:*:*:*:* | |
Vendors & Products |
Nodejs
Nodejs nodejs |
|
Metrics |
ssvc
|
Mon, 26 Aug 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2024-07-09T01:07:28.098Z
Updated: 2024-10-25T17:48:27.567Z
Reserved: 2024-01-04T01:04:06.574Z
Link: CVE-2024-22020
Vulnrichment
Updated: 2024-08-01T22:35:34.646Z
NVD
Status : Awaiting Analysis
Published: 2024-07-09T02:15:09.973
Modified: 2024-10-25T18:35:03.697
Link: CVE-2024-22020
Redhat