CVE-2023-23920

Published: August 31, 2023Last modified: February 18, 2026

Description

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

Severity score breakdown

ParameterValue
Base score4.2
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnodejsNot affected (18.17.1-r0)
StreamnodejsNot affected (18.17.1-r0)
Hardened Containers23 LTSnodejsNot affected (18.17.1-r0)
StreamnodejsNot affected (18.17.1-r0)

References

ON THIS PAGE