Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45545
HistoryFeb 21, 2024 - 3:05 a.m.

Privilege Escalation

2024-02-2103:05:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
node.js
privilege escalation
cap_net_bind_service
bug
unauthorized access

7.5 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%

nodejs is vulnerable to Privilege Escalation. The vulnerability is due to a bug in the implementation of the exception of CAP_NET_BIND_SERVICE, Node.js incorrectly applies this exception even when other capabilities have been set. It potentially allows unprivileged users to execute code with elevated privileges, leading to unauthorized access and control over sensitive resources.

7.5 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%