A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.
History

Fri, 25 Oct 2024 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 25 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Nodejs
Nodejs nodejs
CPEs cpe:2.3:a:nodejs:nodejs:*:*:*:*:*:*:*:*
Vendors & Products Nodejs
Nodejs nodejs
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-07-09T01:07:28.098Z

Updated: 2024-10-25T17:48:27.567Z

Reserved: 2024-01-04T01:04:06.574Z

Link: CVE-2024-22020

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.646Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-09T02:15:09.973

Modified: 2024-10-25T18:35:03.697

Link: CVE-2024-22020

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-07-09T00:00:00Z

Links: CVE-2024-22020 - Bugzilla