PT-2023-2765 · Node.Js+10 · Node.Js+10

Ben Noordhuis

·

Published

2023-02-16

·

Updated

2026-05-18

·

CVE-2023-23920

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions prior to 19.6.1 Node.js versions prior to 18.14.1 Node.js versions prior to 16.19.1 Node.js versions prior to 14.21.3
Description An untrusted search path issue exists that could allow an attacker to search and potentially load ICU data when running with elevated privileges, potentially leading to privilege escalation.
Recommendations For versions prior to 19.6.1, update to version 19.6.1 or later. For versions prior to 18.14.1, update to version 18.14.1 or later. For versions prior to 16.19.1, update to version 16.19.1 or later. For versions prior to 14.21.3, update to version 14.21.3 or later.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

ALSA-2023:1582
ALSA-2023:1583
ALSA-2023:1743
ALSA-2023:2654
ALSA-2023:2655
ALT-PU-2023-1431
ALT-PU-2023-1494
ALT-PU-2023-1496
BDU:2023-02655
BIT-NODE-2023-23920
BIT-NODE-MIN-2023-23920
CESA-2023_1582
CESA-2023_1583
CESA-2023_1743
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2023-23920
DLA-3344-1
DSA-5395-1
DSA-5589-1
MGASA-2023-0078
OESA-2023-1551
OPENSUSE-SU-2024:12725-1
OPENSUSE-SU-2024:12726-1
RHSA-2023:1533
RHSA-2023:1582
RHSA-2023:1583
RHSA-2023:1742
RHSA-2023:1743
RHSA-2023:1744
RHSA-2023:2654
RHSA-2023:2655
RHSA-2023:5533
RHSA-2023_1582
RHSA-2023_1583
RHSA-2023_1743
RHSA-2023_2654
RHSA-2023_2655
RLSA-2023:1582
RLSA-2023:1583
RLSA-2023:1743
RLSA-2023:2655
SUSE-SU-2023:0606-1
SUSE-SU-2023:0607-1
SUSE-SU-2023:0608-1
SUSE-SU-2023:0609-1
SUSE-SU-2023:0673-1
SUSE-SU-2023:0674-1
SUSE-SU-2023:0682-1
SUSE-SU-2023:0715-1
SUSE-SU-2023:0738-1
SUSE-SU-2023_0606-1
SUSE-SU-2023_0682-1
USN-6672-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Node.Js
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu