CVE-2023-23920

CVSS V2 None CVSS V3 None
Description
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
Overview
  • CVE ID
  • CVE-2023-23920
  • Assigner
  • support@hackerone.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-02-23T20:15:14
  • Last Modified Date
  • 2023-03-16T16:15:11
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 1 OR 14.0.0 14.14.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 1 OR 14.0.0 14.21.3
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 1 OR 16.0.0 16.12.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 1 OR 16.0.0 16.19.1
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 1 OR 18.0.0 18.11.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 1 OR 18.0.0 18.14.1
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 1 OR 19.0.0 19.6.1
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 05:23:29 Added to TrackCVE
2023-04-17 05:23:32 Weakness Enumeration new