PT-2023-2003 · Node.Js+7 · Node.Js+7

Goums

·

Published

2023-02-16

·

Updated

2026-05-18

·

CVE-2023-23918

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions prior to 19.6.1 Node.js versions prior to 18.14.1 Node.js versions prior to 16.19.1 Node.js versions prior to 14.21.3
Description A privilege escalation issue exists, related to errors in authorization. This issue can be exploited by a remote attacker to elevate their privileges. The vulnerability allows bypassing the experimental Permissions feature in Node.js, enabling access to non-authorized modules using process.mainModule.require(). This affects users who have enabled the experimental permissions option with --experimental-policy.
Recommendations For versions prior to 19.6.1, update to version 19.6.1 or later. For versions prior to 18.14.1, update to version 18.14.1 or later. For versions prior to 16.19.1, update to version 16.19.1 or later. For versions prior to 14.21.3, update to version 14.21.3 or later. As a temporary workaround, consider disabling the process.mainModule.require() function until a patch is available. Restrict access to non-authorized modules to minimize the risk of exploitation. Avoid using the experimental permissions option with --experimental-policy until the issue is resolved.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALSA-2023:1582
ALSA-2023:1583
ALSA-2023:1743
ALSA-2023:2654
ALSA-2023:2655
ALT-PU-2023-1431
ALT-PU-2023-1494
ALT-PU-2023-1496
AZL-13776
BDU:2023-01627
BIT-NODE-2023-23918
BIT-NODE-MIN-2023-23918
CESA-2023_1582
CESA-2023_1583
CESA-2023_1743
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2023-23918
DSA-5589-1
MGASA-2023-0078
OESA-2023-1551
OPENSUSE-SU-2023_3455-1
OPENSUSE-SU-2024:12725-1
OPENSUSE-SU-2024:12726-1
RHSA-2023:1533
RHSA-2023:1582
RHSA-2023:1583
RHSA-2023:1742
RHSA-2023:1743
RHSA-2023:1744
RHSA-2023:2654
RHSA-2023:2655
RHSA-2023_1582
RHSA-2023_1583
RHSA-2023_1743
RHSA-2023_2654
RHSA-2023_2655
RLSA-2023:1582
RLSA-2023:1583
RLSA-2023:1743
RLSA-2023:2655
SUSE-SU-2023:0607-1
SUSE-SU-2023:0608-1
SUSE-SU-2023:0609-1
SUSE-SU-2023:0673-1
SUSE-SU-2023:0674-1
SUSE-SU-2023:0715-1
SUSE-SU-2023:0738-1
SUSE-SU-2023:3455-1
SUSE-SU-2023_0607-1
SUSE-SU-2023_0608-1
SUSE-SU-2023_0609-1
SUSE-SU-2023_0673-1
SUSE-SU-2023_0674-1
SUSE-SU-2023_0715-1
SUSE-SU-2023_0738-1
SUSE-SU-2023_3455-1

Affected Products

Alt Linux
Almalinux
Centos
Node.Js
Red Hat
Red Os
Rocky Linux
Suse