nodejs: integrity checks according to policies can be circumvented
Published Oct 18, 2023
7.5
HIGHCVSS 3.1
EPSS 1.11%
Description
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.*
- Version 11.0StatusaffectedConstraints<11.*
- Version 12.0StatusaffectedConstraints<12.*
- Version 13.0StatusaffectedConstraints<13.*
- Version 14.0StatusaffectedConstraints<14.*
- Version 15.0StatusaffectedConstraints<15.*
- Version 16.0StatusaffectedConstraints<16.*
- Version 17.0StatusaffectedConstraints<17.*
- Version 18.0StatusaffectedConstraints<18.18.2
- Version 19.0StatusaffectedConstraints<19.*
- Version 20.0StatusaffectedConstraints<20.8.1
- Version 4.0StatusaffectedConstraints<4.*
- Version 5.0StatusaffectedConstraints<5.*
- Version 6.0StatusaffectedConstraints<6.*
- Version 7.0StatusaffectedConstraints<7.*
- Version 8.0StatusaffectedConstraints<8.*
- Version 9.0StatusaffectedConstraints<9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Node.js | Node | unaffected |
|
Configuration 1
Configuration 2
- 37
- 38
- 39
No data.
Red Hat Enterprise Linux 8
nodejs:18-8080020231015215042.63b34585
Fixed · RHSA-2023:5869
Red Hat Enterprise Linux 8
nodejs:20-8090020231019152822.a75119d5
Fixed · RHSA-2023:7205
Red Hat Enterprise Linux 9
nodejs:18-9020020231015221156.rhel9
Fixed · RHSA-2023:5849
Red Hat Enterprise Linux 8
nodejs:16/nodejs
Will not fix
Red Hat Enterprise Linux 9
nodejs
Will not fix
Red Hat Enterprise Linux 9
nodejs:20/nodejs
Affected
Red Hat Software Collections
rh-nodejs14-nodejs
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:18-8080020231015215042.63b34585 | Fixed | RHSA-2023:5869 |
| Red Hat Enterprise Linux 8 | nodejs:20-8090020231019152822.a75119d5 | Fixed | RHSA-2023:7205 |
| Red Hat Enterprise Linux 9 | nodejs:18-9020020231015221156.rhel9 | Fixed | RHSA-2023:5849 |
| Red Hat Enterprise Linux 8 | nodejs:16/nodejs | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | nodejs | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | nodejs:20/nodejs | Affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerability is triggered in an experimental feature that is not widely deployed at the time this vulnerability was disclosed, which is why Red Hat has marked this vulnerability as moderate.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-38552 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2244415 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-42351 Advisory
- https://hackerone.com/reports/2094235 Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-38552
- https://security.netapp.com/advisory/ntap-20231116-0013/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241108-0002/
- https://www.cve.org/CVERecord?id=CVE-2023-38552
Change history (0)
No recorded changes yet.