UBUNTU-CVE-2023-32002
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-32002
UBUNTU-CVE-2023-32002
Summary:
Details: The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.
References: https://ubuntu.com/security/CVE-2023-32002, https://nodejs.org/en/blog/vulnerability/august-2023-security-releases#permissions-policies-can-be-bypassed-via-module_load-highcve-2023-32002, https://github.com/nodejs/node/commit/15bced0bde93f24115b779a309d517845c87e17a, https://github.com/nodejs/node/commit/b68e5e798138be0041ba9ace72d8d45e63c068a1, https://www.cve.org/CVERecord?id=CVE-2023-32002, https://ubuntu.com/security/notices/USN-6822-1
Affected packages
Package
Name: nodejs
Purl: pkg:deb/ubuntu/[email protected]~dfsg-1ubuntu3.6?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
