Lack of data validation In nodejs
Description
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 18.20.4+dfsg-1~deb12u1 | ||
alpine v3.19 | 20.15.1-r0 | ||
alpine v3.20 | 20.15.1-r0 | ||
alpine v3.21 | 20.15.1-r0 | ||
alpine v3.22 | 20.15.1-r0 | ||
debian 13 | 20.15.1+dfsg-1 | ||
debian 14 | 20.15.1+dfsg-1 | ||
alpine v3.23 | 20.15.1-r0 | ||
rpm rhel8 | 1:18.20.4-1.module+el8.10.0+22199+56ea0ead | ||
rpm rhel10 | - | - |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5. 6. 7.