Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5589-1 | nodejs security update |
EUVD |
EUVD-2023-28000 | A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy. |
Wed, 12 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-05-08T16:15:23.012Z
Reserved: 2023-01-19T00:00:00.000Z
Link: CVE-2023-23918
Updated: 2024-08-02T10:42:27.095Z
Status : Modified
Published: 2023-02-23T20:15:13.920
Modified: 2025-05-08T17:16:00.237
Link: CVE-2023-23918
OpenCVE Enrichment
No data.
Debian DSA
EUVD