Lucene search

K

Deno Security Vulnerabilities

cve
cve

CVE-2023-28446

Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Arbitrary program names without any ANSI filtering allows any malicious program to clear the first 2 lines of a op_spawn_child or op_kill prompt and replace it with any desired text. This...

8.8CVSS

8.6AI Score

0.002EPSS

2023-03-24 08:15 PM
16
cve
cve

CVE-2023-26103

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s,s/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used...

7.5CVSS

7.5AI Score

0.001EPSS

2023-02-25 05:15 AM
23
cve
cve

CVE-2022-24783

Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This...

10CVSS

9.6AI Score

0.002EPSS

2022-03-25 10:15 PM
68
cve
cve

CVE-2023-33966

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in node:http or node:https modules are incorrectly not checked against the network permission allow list (--allow-net). Dependencies relying on these built-in...

9.8CVSS

9.4AI Score

0.002EPSS

2023-05-31 06:15 PM
15
cve
cve

CVE-2023-28445

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the...

9.9CVSS

9.3AI Score

0.001EPSS

2023-03-24 12:15 AM
37
cve
cve

CVE-2023-22499

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to unrelated action. A malicious program could clear the...

7.5CVSS

7.3AI Score

0.002EPSS

2023-01-17 09:15 PM
142
cve
cve

CVE-2021-41641

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any...

8.4CVSS

8.6AI Score

0.0005EPSS

2022-06-12 01:15 PM
43
6
cve
cve

CVE-2021-42139

Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain...

9.8CVSS

9.6AI Score

0.007EPSS

2021-10-11 05:15 AM
35
cve
cve

CVE-2021-32619

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through import() or new Worker might have been able to bypass network and file system permission checks when statically importing other...

9.8CVSS

9.5AI Score

0.003EPSS

2021-05-28 09:15 PM
69
3