Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39326
HistoryFeb 18, 2023 - 4:53 a.m.

Improper Access Control

2023-02-1804:53:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27
nodejs
improper access control
remote attacker
security bypass
icu_data
vulnerability
search
load

EPSS

0

Percentile

14.1%

nodejs is vulnerable to Improper Access Control. A remote authenticated attacker is able to bypass security restrictions by sending a specially-crafted request using ICU_DATA environment variable, An attacker could exploit this vulnerability to search and potentially load ICU data.