CVE-2023-33966

HIGH

Deno 1.34.0 - Improper Privilege Management in Node HTTP/HTTPS Modules

Title source: llm
STIX 2.1

Description

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too. Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected. This problem has been patched in Deno v1.34.1 and deno_runtime 0.114.1 and all users are recommended to update to this version. No workaround is available for this issue.

References (2)

Core 2
Core References

Scores

CVSS v3 8.6
EPSS 0.0063
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-269 CWE-276
Status published
Products (4)
crates.io/deno 1.34.0 - 1.34.1crates.io
crates.io/deno_runtime 0.114.0 - 0.115.0crates.io
deno/deno 1.34.0
deno/deno_runtime 0.114.0
Published May 31, 2023
Tracked Since Feb 18, 2026