Wind River Support Network

HomeDefectsLIN1022-4601
Fixed

LIN1022-4601 : Security Advisory - nodejs - CVE-2023-30581

Created: Jun 24, 2023    Updated: Nov 23, 2023
Resolved Date: Aug 12, 2023
Found In Version: 10.22.33.1
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definition. This vulnerability affects all users using the experimental policy mechanism in all active release lines: v16, v18 and, v20.

Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js

https://nvd.nist.gov/vuln/detail/CVE-2023-30581

CVEs


Live chat
Online