Liberica NIK24.2.1+1 (JDK 24.0.1+11)Security Advisory
Search Cve

CVE-2024-36138

Published: July 12, 2024Last modified: November 5, 2024

Description

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Severity score breakdown

ParameterValue
Base score8.1
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Liberica NIK23 (JDK 17)standard (nodejs)Fixed (23.0.6+1)
23 (JDK 21)standard (nodejs)Fixed (23.1.5+1)
24 (JDK 23)nodejsFixed (24.1.1+1)

References

Published BELL-SAs

ON THIS PAGE