icon

We found results for “

CVE-2023-32559

Date: August 23, 2023

A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API "process.binding()" can bypass the policy mechanism by requiring internal modules and eventually take advantage of "process.binding('spawn_sync')" run arbitrary code, outside of the limits defined in a "policy.json" file. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Insufficient Information

NVD-CWE-noinfo

Improper Privilege Management

CWE-269

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us