ALPINE-CVE-2023-23920 PUBLISHED CVSS 4.199999809265137 MEDIUM

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

Risk Scores

CVSS v3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.21nodejs0, 0, 0
Alpine:v3.17nodejs10.16.3-r0, 12.13.0-r0, 12.13.1-r0
Alpine:v3.19nodejs10.14.1-r0, 10.13.0-r0, 0
Alpine:v3.23nodejs0, 0, 0
Alpine:v3.16nodejs14.15.4-r0, 0, 10.13.0-r0
Alpine:v3.22nodejs0, 0, 0
Alpine:v3.15nodejs8.11.1-r2, 8.11.1-r1, 8.11.1-r0
Alpine:v3.14nodejs0, 8.9.4-r0, 8.9.3-r1
Alpine:v3.20nodejs8.9.0-r0, 10.15.3-r0, 10.16.0-r0
Alpine:v3.18nodejs14.18.1-r1, 6.10.0-r0, 4.5.0-r0

Timeline

References

Open in Interactive Console →