Lucene search

K
f5F5F5:K000134602
HistoryMay 15, 2023 - 12:00 a.m.

K000134602 : Node.js vulnerabilities CVE-2023-23918 and CVE-2023-23920

2023-05-1500:00:00
my.f5.com
12
node.js
vulnerabilities
cve-2023-23918
cve-2023-23920
privilege escalation
untrusted search path
icu data

AI Score

4.8

Confidence

High

EPSS

0.002

Percentile

53.6%

Security Advisory Description

  • CVE-2023-23918
    A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https****:****//nodejs**.**org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.
  • CVE-2023-23920
    An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

Impact

There is no impact; F5 products are not affected by these vulnerabilities.