PT-2023-4547 · Node.Js+10 · Node.Js+10

Mattaustin

·

Published

2023-08-09

·

Updated

2025-07-02

·

CVE-2023-32002

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 16.x through 20.x
Description The issue is related to the Module. load() function, which can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This affects users using the experimental policy mechanism in all active release lines. The policy is an experimental feature of Node.js.
Recommendations For Node.js versions 16.x through 20.x, update to a version that includes the fix for the issue, as the policy mechanism can be bypassed via Module. load(). At the moment, there is no information about a newer version that contains a fix for this vulnerability, however, it is mentioned that the issue is fixed in an unofficial release.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5360
ALSA-2023:5362
ALSA-2023:5363
ALSA-2023:5532
ALT-PU-2023-6858
ALT-PU-2024-14696
ALT-PU-2025-2007
ALT-PU-2025-2047
AZL-27940
AZL-27942
BDU:2023-04953
BIT-NODE-2023-32002
BIT-NODE-MIN-2023-32002
CESA-2023_5360
CESA-2023_5362
CVE-2023-32002
DSA-5589-1
MGASA-2023-0264
OESA-2023-1551
OPENSUSE-SU-2023_3378-1
OPENSUSE-SU-2023_3379-1
OPENSUSE-SU-2023_3408-1
OPENSUSE-SU-2023_3455-1
OPENSUSE-SU-2024:13117-1
RHSA-2023:5360
RHSA-2023:5361
RHSA-2023:5362
RHSA-2023:5363
RHSA-2023:5532
RHSA-2023:5533
RHSA-2023_5360
RHSA-2023_5362
RHSA-2023_5363
RHSA-2023_5532
RLSA-2023:5363
RLSA-2023:5532
SUSE-SU-2023:3306-1
SUSE-SU-2023:3355-1
SUSE-SU-2023:3356-1
SUSE-SU-2023:3378-1
SUSE-SU-2023:3379-1
SUSE-SU-2023:3400-1
SUSE-SU-2023:3408-1
SUSE-SU-2023:3455-1
SUSE-SU-2023_3355-1
SUSE-SU-2023_3356-1
SUSE-SU-2023_3378-1
SUSE-SU-2023_3379-1
SUSE-SU-2023_3400-1
USN-6822-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Node.Js
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu