CVE-2023-38552
HIGHNode.js 18.0.0-18.18.0 and 20.x - Policy Integrity Check Bypass via Forged Checksum
Title source: llmDescription
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.
References (9)
Core 9
Core References
Third Party Advisory
https://hackerone.com/reports/2094235
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20231116-0013/
Vendor Advisory
https://security.netapp.com/advisory/ntap-20241108-0002/
Scores
CVSS v3
7.5
EPSS
0.0111
EPSS Percentile
61.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-345
Status
published
Products (4)
fedoraproject/fedora
37
fedoraproject/fedora
38
fedoraproject/fedora
39
nodejs/node.js
18.0.0 - 18.18.1
Published
Oct 18, 2023
Tracked Since
Feb 18, 2026