CVE-2023-23918

Source
https://cve.org/CVERecord?id=CVE-2023-23918
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-23918.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-23918
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLEANSTART (13)
DEBIAN (1)
MGASA (1)
OESA (1)
openSUSE (2)
RHSA (8)
RLSA (5)
SUSE (8)
UBUNTU (1)
Related
Published
2023-02-23T00:00:00Z
Modified
2026-08-12T03:51:22Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

Database specific
{
    "cna_assigner":  "hackerone",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/23xxx/CVE-2023-23918.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "4.0"
                },
                {
                    "fixed":  "4.*"
                },
                {
                    "introduced":  "5.0"
                },
                {
                    "fixed":  "5.*"
                },
                {
                    "introduced":  "6.0"
                },
                {
                    "fixed":  "6.*"
                },
                {
                    "introduced":  "7.0"
                },
                {
                    "fixed":  "7.*"
                },
                {
                    "introduced":  "8.0"
                },
                {
                    "fixed":  "8.*"
                },
                {
                    "introduced":  "9.0"
                },
                {
                    "fixed":  "9.*"
                },
                {
                    "introduced":  "10.0"
                },
                {
                    "fixed":  "10.*"
                },
                {
                    "introduced":  "11.0"
                },
                {
                    "fixed":  "11.*"
                },
                {
                    "introduced":  "12.0"
                },
                {
                    "fixed":  "12.*"
                },
                {
                    "introduced":  "13.0"
                },
                {
                    "fixed":  "13.*"
                },
                {
                    "introduced":  "14.0"
                },
                {
                    "fixed":  "14.21.3"
                },
                {
                    "introduced":  "15.0"
                },
                {
                    "fixed":  "15.*"
                },
                {
                    "introduced":  "16.0"
                },
                {
                    "fixed":  "16.19.1"
                },
                {
                    "introduced":  "17.0"
                },
                {
                    "fixed":  "17.*"
                },
                {
                    "introduced":  "18.0"
                },
                {
                    "fixed":  "18.14.1"
                },
                {
                    "introduced":  "19.0"
                },
                {
                    "fixed":  "19.6.1"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/nodejs/node

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/node
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "14.0.0"
        },
        {
            "last_affected":  "14.14.0"
        },
        {
            "fixed":  "14.21.3"
        },
        {
            "introduced":  "16.0.0"
        },
        {
            "last_affected":  "16.12.0"
        },
        {
            "fixed":  "16.19.1"
        },
        {
            "introduced":  "18.0.0"
        },
        {
            "last_affected":  "18.11.0"
        },
        {
            "fixed":  "18.14.1"
        },
        {
            "introduced":  "19.0.0"
        },
        {
            "fixed":  "19.6.1"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v14.*
v14.0.0
v14.1.0
v14.10.0
v14.10.1
v14.11.0
v14.12.0
v14.13.0
v14.13.1
v14.14.0
v14.15.0
v14.15.1
v14.15.2
v14.15.3
v14.15.4
v14.15.5
v14.16.0
v14.16.1
v14.17.0
v14.17.1
v14.17.2
v14.17.3
v14.17.4
v14.17.5
v14.17.6
v14.18.0
v14.18.1
v14.18.2
v14.18.3
v14.19.0
v14.19.1
v14.19.2
v14.19.3
v14.2.0
v14.20.0
v14.20.1
v14.21.0
v14.21.1
v14.21.2
v14.3.0
v14.4.0
v14.5.0
v14.6.0
v14.7.0
v14.8.0
v14.9.0
v16.*
v16.0.0
v16.1.0
v16.10.0
v16.11.0
v16.11.1
v16.12.0
v16.13.0
v16.13.1
v16.13.2
v16.14.0
v16.14.1
v16.14.2
v16.15.0
v16.15.1
v16.16.0
v16.17.0
v16.17.1
v16.18.0
v16.18.1
v16.19.0
v16.2.0
v16.3.0
v16.4.0
v16.4.1
v16.4.2
v16.5.0
v16.6.0
v16.6.1
v16.6.2
v16.7.0
v16.8.0
v16.9.0
v16.9.1
v18.*
v18.0.0
v18.1.0
v18.10.0
v18.11.0
v18.12.0
v18.12.1
v18.13.0
v18.14.0
v18.2.0
v18.3.0
v18.4.0
v18.5.0
v18.6.0
v18.7.0
v18.8.0
v18.9.0
v18.9.1
v19.*
v19.0.0
v19.0.1
v19.1.0
v19.2.0
v19.3.0
v19.4.0
v19.5.0
v19.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-23918.json"