nodejs 安全漏洞 (CVE-2023-30585)

admin 2023-11-29 17:42:32 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
nodejs 安全漏洞 (CVE-2023-30585)

CVE编号

CVE-2023-30585

利用情况

暂无

补丁情况

N/A

披露时间

2023-11-28
漏洞描述
A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users who install Node.js using the .msi installer. This vulnerability emerges during the repair operation, where the "msiexec.exe" process, running under the NT AUTHORITY\SYSTEM context, attempts to read the %USERPROFILE% environment variable from the current user's registry. The issue arises when the path referenced by the %USERPROFILE% environment variable does not exist. In such cases, the "msiexec.exe" process attempts to create the specified path in an unsafe manner, potentially leading to the creation of arbitrary folders in arbitrary locations. The severity of this vulnerability is heightened by the fact that the %USERPROFILE% environment variable in the Windows registry can be modified by standard (or "non-privileged") users. Consequently, unprivileged actors, including malicious entities or trojans, can manipulate the environment variable key to deceive the privileged "msiexec.exe" process. This manipulation can result in the creation of folders in unintended and potentially malicious locations. It is important to note that this vulnerability is specific to Windows users who install Node.js using the .msi installer. Users who opt for other installation methods are not affected by this particular issue.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://nodejs.org/en/blog/vulnerability/june-2023-security-releases
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 debian_10 nodejs * Up to (excluding) 10.24.0~dfsg-1~deb10u1
运行在以下环境
系统 debian_11 nodejs * Up to (excluding) 12.22.12~dfsg-1~deb11u4
运行在以下环境
系统 debian_12 nodejs * Up to (excluding) 18.13.0+dfsg1-1
运行在以下环境
系统 debian_sid nodejs * Up to (excluding) 18.13.0+dfsg1-1.1
运行在以下环境
系统 fedora_37 nodejs16-npm-8.19.4-1.16.20.1.1.fc37.i686.rpm ( * Up to (excluding) 18.16.1-1.fc37
运行在以下环境
系统 fedora_38 nodejs16-npm-8.19.4-1.16.20.1.1.fc38.x86_64.rpm ( * Up to (excluding) 18.16.1-1.fc38
运行在以下环境
系统 opensuse_Leap_15.4 nodejs16 * Up to (excluding) 18.16.1-150400.9.9.1
运行在以下环境
系统 opensuse_Leap_15.5 nodejs18-docs * Up to (excluding) 18.16.1-150400.9.9.1
CVSS3评分 N/A
  • 攻击路径 N/A
  • 攻击复杂度 N/A
  • 权限要求 N/A
  • 影响范围 N/A
  • 用户交互 N/A
  • 可用性 N/A
  • 保密性 N/A
  • 完整性 N/A
N/A
CWE-ID 漏洞类型
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0