216.73.216.197

CVE-2024-22020

· Published 09/07/2024 02:15 · Modified 09/07/2024 18:19

Labels: CVE-2024-22020 2024-07-09CVE-2024-22020CWE-284[email protected]

Essential information

Published
09/07/2024 02:15
Modified
09/07/2024 18:19
Author
Creator
CVSS
6.5 MEDIUM (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

CVSS metrics

Description

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References