PT-2022-16876 · Deno · Deno

Aapoalas

+2

·

Published

2022-03-25

·

Updated

2023-06-30

·

CVE-2022-24783

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deno versions 1.18.0 through 1.20.2
Description The issue allows a malicious actor controlling the code executed in a Deno runtime to bypass all permission checks and execute arbitrary shell code. This does not affect users of Deno Deploy. The cause of this error was that certain FFI operations did not correctly check for permissions.
Recommendations For Deno versions 1.18.0 through 1.20.2, upgrade to Deno 1.20.3 immediately, as this version includes the patch for the issue. There is no workaround for this issue, so upgrading is the recommended course of action.

Exploit

Fix

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-24783
GHSA-838H-JQP6-CF2F

Affected Products

Deno