CVE-2023-39331: Path Traversal
A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Other sources
A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations.
References: https://nodejs.org/en/blog/vulnerability/october-2023-security-releases
— Red Hat
FasterXML Jackson Core is vulnerable to a denial of service, caused by improper input validation by the StreamReadConstraints value field. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39331?
CVE-2023-39331 is a path traversal vulnerability in Node.js.
What is the severity of CVE-2023-39331?
The severity of CVE-2023-39331 is high, with a CVSS score of 7.7.
How does CVE-2023-39331 arise?
CVE-2023-39331 arises due to insufficient patching of a previously disclosed vulnerability (CVE-2023-30584) in commit 205f1e6 of Node.js.
Which version of Node.js is affected by CVE-2023-39331?
Node.js versions up to and excluding 20.8.0 are affected by CVE-2023-39331.
Is there a fix for CVE-2023-39331?
Yes, the vulnerability can be fixed by applying the necessary patches and updates provided by the Node.js project.