Permissions, Privileges, and Access Controls in Node.js - CVE-2025-23083

 

Permissions, Privileges, and Access Controls in Node.js - CVE-2025-23083

Published: January 22, 2025


Vulnerability identifier: #VU103222
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23083
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to improperly imposed security restrictions when handling diagnostics data with diagnostics_channel utility. A remote user can hook the utility to internal workers and gain access to sensitive information.


Affected software

Node.js
Gentoo Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Web and Scripting Module
openSUSE Leap
openEuler
Fedora
EasyApache
IBM Business Automation Workflow
APEX Cloud Platform for Red Hat OpenShift
PowerProtect Data Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
npm
v8-devel
nodejs-debuginfo
nodejs-devel
nodejs
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-debugsource
nodejs20
nodejs20-debugsource
npm20
nodejs20-devel
nodejs20-debuginfo
corepack20
nodejs20-docs
net-libs/nodejs
nodejs22
nodejs22-debugsource
nodejs22-devel
npm22
nodejs22-debuginfo
nodejs22-docs
corepack22
nodejs-packaging
nodejs-packaging-bundler
Oracle GraalVM for JDK
APEX Cloud Platform for Microsoft Azure

How to mitigate CVE-2025-23083

Install updates from vendor's website.

Node.js - addressed in versions 20.18.2, 22.13.1, 23.6.1
EasyApache - update to 4 25-4
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
nodejs-nodemon - update to 3.0.1-1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
npm - update to 10.8.2-1.20.18.2.1
npm - update to 10.8.2-1.20.18.2.1
v8-devel - update to 11.3.244.8-1.20.18.2.1
PowerProtect Data Manager - update to 19.19.0-15
nodejs-debuginfo - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs-libs - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-debugsource - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs20 - addressed in versions 20.18.2-2.fc40, 20.18.2-2.fc41, 20.18.2-2.fc42
nodejs20-debugsource - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
npm20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-devel - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-debuginfo - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
corepack20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-docs - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
net-libs/nodejs - update to 22.13.1
nodejs22 - addressed in versions 22.13.1-1.fc41, 22.14.0-2.fc41
nodejs22-debugsource - update to 22.13.1-150600.13.6.1
nodejs22 - update to 22.13.1-150600.13.6.1
nodejs22-devel - update to 22.13.1-150600.13.6.1
npm22 - update to 22.13.1-150600.13.6.1
nodejs22-debuginfo - update to 22.13.1-150600.13.6.1
nodejs22-docs - update to 22.13.1-150600.13.6.1
corepack22 - update to 22.13.1-150600.13.6.1
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4

External References

Related Security Bulletins