SUSE update for nodejs18

Published: 2023-03-13

Security Bulletin


This security bulletin contains information about 5 vulnerabilities.



1) Permissions, Privileges, and Access Controls


EUVDB-ID: #VU72398


Risk: Medium


CVSSv3.1:


CVE-ID: CVE-2023-23918


CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls


Exploit availability: No


Description

The vulnerability allows a remote user to bypass implemented security restrictions.


The vulnerability exists due to improperly imposed security restrictions within the process.mainModule.require() method. A remote user can access non authorized modules.


Mitigation

Update the affected package nodejs18 to the latest version.


Vulnerable software versions

Web and Scripting Module: 12


SUSE Linux Enterprise Server for SAP Applications 12: SP1 - SP5


SUSE Linux Enterprise Server 12: SP1 - SP5


SUSE Linux Enterprise High Performance Computing 12: SP2 - SP5


SUSE Linux Enterprise Server for SAP Applications: 12-SP4


SUSE Linux Enterprise Server: 12-SP2-LTSS-ERICSSON


nodejs18-docs: before 18.14.2-8.6.2


nodejs18-debugsource: before 18.14.2-8.6.2


nodejs18-debuginfo: before 18.14.2-8.6.2


nodejs18-devel: before 18.14.2-8.6.2


nodejs18: before 18.14.2-8.6.2


npm18: before 18.14.2-8.6.2


CPE2.3
External links

http://www.suse.com/support/update/announcement/2023/suse-su-20230715-1/


Q & A


Can this vulnerability be exploited remotely?


Is there known malware, which exploits this vulnerability?




2) Resource management error


EUVDB-ID: #VU72399


Risk: Medium


< ..

Support the originator by clicking the read the rest link below.