PT-2023-7025 · Node.Js+6 · Node.Js+6

Dittyroma

·

Publicado

2023-07-28

·

Atualizado

2026-05-18

·

CVE-2023-39333

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions prior to the fixed version
Description Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. This issue affects users of any active release line of Node.js, but the vulnerable feature is only available if Node.js is started with the --experimental-wasm-modules command line option.
Recommendations As a temporary workaround, consider disabling the --experimental-wasm-modules command line option until a patch is available. Restrict access to the WebAssembly module to minimize the risk of exploitation. Avoid using the vulnerable feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Improper Neutralization

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:5849
ALSA-2023:5869
ALSA-2023:7205
BDU:2023-08046
BIT-NODE-2023-39333
BIT-NODE-MIN-2023-39333
CESA-2023_5869
CESA-2023_7205
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2023-39333
DSA-5589-1
MGASA-2023-0299
OPENSUSE-SU-2023_4207-1
OPENSUSE-SU-2024:13337-1
OPENSUSE-SU-2024:13340-1
RHSA-2023:5849
RHSA-2023:5869
RHSA-2023:7205
RHSA-2023_5849
RHSA-2023_5869
RHSA-2023_7205
RLSA-2023:7205
SUSE-SU-2023:4132-1
SUSE-SU-2023:4133-1
SUSE-SU-2023:4150-1
SUSE-SU-2023:4155-1
SUSE-SU-2023:4207-1

Produtos afetados

Almalinux
Centos
Node.Js
Red Hat
Red Os
Rocky Linux
Suse