VDB
BDU%3A2024-01672
BDU%3A2024-01672
PUBLISHED
CVSS 10 CRITICAL
Уязвимость программной платформы Node.js, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код с повышенными привилегиями
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Node.js Foundation | Red Hat Enterprise Linux, Node.js |
Timeline
- Feb 29, 2024 CVE Published
- Mar 1, 2024 CVE Updated
References
- https://nodejs.org/en/blog/release/v20.11.1 url
- https://nodejs.org/en/blog/vulnerability/february-2024-security-releases/#code-injection-and-privilege-escalation-through-linux-capabilities-cve-2024-21892---high url
- https://access.redhat.com/security/cve/cve-2024-21892 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2264582 url
- https://github.com/nodejs/node/commit/e6b4c105e0795fba8afb3f8e910c56ba9e60f4b5 url
- https://github.com/nodejs/node/commit/10ecf400679e04eddab940721cad3f6c1d603b61 url