Back

HIGH

nodejs: integrity checks according to policies can be circumvented

Published Oct 18, 2023

Description

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

Affected products

Remediation

Red Hat statement

The vulnerability is triggered in an experimental feature that is not widely deployed at the time this vulnerability was disclosed, which is why Red Hat has marked this vulnerability as moderate.

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Oct 18, 2023
Updated Nov 3, 2025
Reserved Jul 20, 2023
CISA Vulnrichment
Updated Feb 20, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 13, 2023
ENISA EUVD
Assigner hackerone
Published Oct 18, 2023
Updated Nov 3, 2025
Exploited since n/a
EUVD-2023-42351