CVE Vulnerabilities

CVE-2024-22020

Published: Jul 09, 2024 | Modified: Nov 22, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
Ubuntu
MEDIUM

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

Affected Software

Name Vendor Start Version End Version
Nodejs Ubuntu mantic *
Nodejs Ubuntu trusty/esm *
Nodejs Ubuntu upstream *
Red Hat Enterprise Linux 8 RedHat nodejs:20-8100020240808073736.489197e6 *
Red Hat Enterprise Linux 8 RedHat nodejs:18-8100020240807161023.489197e6 *
Red Hat Enterprise Linux 9 RedHat nodejs:20-9040020240807145403.rhel9 *
Red Hat Enterprise Linux 9 RedHat nodejs:18-9040020240807131341.rhel9 *

References