UBUNTU-CVE-2023-23920
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-23920
UBUNTU-CVE-2023-23920
Summary:
Details: An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
References: https://ubuntu.com/security/CVE-2023-23920, https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/#node-js-insecure-loading-of-icu-data-through-icu_data-environment-variable-low-cve-2023-23920, https://github.com/nodejs/node/commit/f369c0a739b9f0182ededa834a2a44e6fec322d1, https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/, https://ubuntu.com/security/notices/USN-6672-1, https://www.cve.org/CVERecord?id=CVE-2023-23920
Affected packages
Package
Name: nodejs
Purl: pkg:deb/ubuntu/[email protected]~dfsg-3ubuntu1.5?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
