SB2023053078 - Improper privilege management in Deno
Published: May 30, 2023 Updated: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper privilege management (CVE-ID: CVE-2023-33966)
The vulnerability allows a remote attacker to bypass network access restrictions.
The vulnerability exists due to improper privilege management in built-in "node:http" and "node:https" modules when making outbound HTTP requests. A remote attacker can cause the application to use these built-in modules to bypass network access restrictions.
Dependencies relying on these built-in modules are also affected. Deno Deploy users are unaffected.
Remediation
Install update from vendor's website.