PT-2023-4549 · Node.Js+9 · Node.Js+9

Leodog896

·

Published

2023-08-09

·

Updated

2025-07-01

·

CVE-2023-32559

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 16.x through 20.x
Description A privilege escalation issue exists in the experimental policy mechanism due to inadequate access controls. This can be exploited by a remote attacker to bypass existing security restrictions. The use of the deprecated API process.binding() can bypass the policy mechanism, allowing an attacker to require internal modules and eventually execute arbitrary code outside of the limits defined in a policy.json file. The policy is an experimental feature of Node.js.
Recommendations For Node.js versions 16.x through 20.x, consider disabling the use of the deprecated API process.binding() as a temporary workaround until a patch is available. Restrict access to internal modules to minimize the risk of exploitation. Avoid using process.binding('spawn sync') in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALSA-2023:5360
ALSA-2023:5362
ALSA-2023:5363
ALSA-2023:5532
ALT-PU-2023-6858
ALT-PU-2024-14696
ALT-PU-2025-2007
ALT-PU-2025-2047
AZL-27973
AZL-27974
BDU:2023-04955
BIT-NODE-2023-32559
BIT-NODE-MIN-2023-32559
CESA-2023_5360
CESA-2023_5362
CVE-2023-32559
DLA-3886-1
DSA-5589-1
MGASA-2023-0264
OESA-2023-1551
OPENSUSE-SU-2023_3378-1
OPENSUSE-SU-2023_3379-1
OPENSUSE-SU-2023_3408-1
OPENSUSE-SU-2023_3455-1
OPENSUSE-SU-2024:13117-1
RHSA-2023:5360
RHSA-2023:5361
RHSA-2023:5362
RHSA-2023:5363
RHSA-2023:5532
RHSA-2023:5533
RHSA-2023_5360
RHSA-2023_5362
RHSA-2023_5363
RHSA-2023_5532
RLSA-2023:5363
RLSA-2023:5532
SUSE-SU-2023:3306-1
SUSE-SU-2023:3355-1
SUSE-SU-2023:3356-1
SUSE-SU-2023:3378-1
SUSE-SU-2023:3379-1
SUSE-SU-2023:3400-1
SUSE-SU-2023:3408-1
SUSE-SU-2023:3455-1
USN-6822-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Node.Js
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu