Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-23920

Published: August 31, 2023Last modified: August 31, 2023

Description

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

Severity score breakdown

ParameterValue
Base score4.2
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnodejsNot affected (18.17.1-r0)
StreamnodejsNot affected (18.17.1-r0)

References

ON THIS PAGE