VDB

BIT-node-2023-23920

BIT-node-2023-23920 PUBLISHED CVSS 4.199999809265137 MEDIUM

An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.

Risk Scores

CVSS 3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Bitnaminode14.0.0, 16.0.0, 18.0.0

Timeline

  • Mar 6, 2024 CVE Published
  • Apr 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›