SB2024030583 - Input validation error in Deno



SB2024030583 - Input validation error in Deno

Published: March 5, 2024 Updated: April 23, 2026

Security Bulletin ID SB2024030583
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2024-27932)

The vulnerability allows a remote user to disclose sensitive information and modify request integrity.

The vulnerability exists due to improper input validation in DENO_AUTH_TOKENS hostname matching in auth_tokens.rs when processing import specifiers. A remote user can cause a token to be sent to an attacker-controlled server to disclose sensitive information and modify request integrity.

User interaction is required, and the issue affects scenarios where potentially untrusted code is imported while DENO_AUTH_TOKENS is in use.


Remediation

Install update from vendor's website.