Permissions, Privileges, and Access Controls in Node.js - CVE-2025-23083
Published: January 22, 2025
Vulnerability identifier: #VU103222
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23083
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to improperly imposed security restrictions when handling diagnostics data with diagnostics_channel utility. A remote user can hook the utility to internal workers and gain access to sensitive information.
Affected software
Node.js
Gentoo Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Web and Scripting Module
openSUSE Leap
openEuler
Fedora
EasyApache
IBM Business Automation Workflow
APEX Cloud Platform for Red Hat OpenShift
PowerProtect Data Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
npm
v8-devel
nodejs-debuginfo
nodejs-devel
nodejs
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-debugsource
nodejs20
nodejs20-debugsource
npm20
nodejs20-devel
nodejs20-debuginfo
corepack20
nodejs20-docs
net-libs/nodejs
nodejs22
nodejs22-debugsource
nodejs22-devel
npm22
nodejs22-debuginfo
nodejs22-docs
corepack22
nodejs-packaging
nodejs-packaging-bundler
Oracle GraalVM for JDK
APEX Cloud Platform for Microsoft Azure
Gentoo Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Web and Scripting Module
openSUSE Leap
openEuler
Fedora
EasyApache
IBM Business Automation Workflow
APEX Cloud Platform for Red Hat OpenShift
PowerProtect Data Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
npm
v8-devel
nodejs-debuginfo
nodejs-devel
nodejs
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-debugsource
nodejs20
nodejs20-debugsource
npm20
nodejs20-devel
nodejs20-debuginfo
corepack20
nodejs20-docs
net-libs/nodejs
nodejs22
nodejs22-debugsource
nodejs22-devel
npm22
nodejs22-debuginfo
nodejs22-docs
corepack22
nodejs-packaging
nodejs-packaging-bundler
Oracle GraalVM for JDK
APEX Cloud Platform for Microsoft Azure
How to mitigate CVE-2025-23083
Install updates from vendor's website.
Node.js - addressed in versions 20.18.2, 22.13.1, 23.6.1
EasyApache - update to 4 25-4
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
nodejs-nodemon - update to 3.0.1-1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
npm - update to 10.8.2-1.20.18.2.1
npm - update to 10.8.2-1.20.18.2.1
v8-devel - update to 11.3.244.8-1.20.18.2.1
PowerProtect Data Manager - update to 19.19.0-15
nodejs-debuginfo - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs-libs - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-debugsource - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs20 - addressed in versions 20.18.2-2.fc40, 20.18.2-2.fc41, 20.18.2-2.fc42
nodejs20-debugsource - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
npm20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-devel - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-debuginfo - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
corepack20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-docs - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
net-libs/nodejs - update to 22.13.1
nodejs22 - addressed in versions 22.13.1-1.fc41, 22.14.0-2.fc41
nodejs22-debugsource - update to 22.13.1-150600.13.6.1
nodejs22 - update to 22.13.1-150600.13.6.1
nodejs22-devel - update to 22.13.1-150600.13.6.1
npm22 - update to 22.13.1-150600.13.6.1
nodejs22-debuginfo - update to 22.13.1-150600.13.6.1
nodejs22-docs - update to 22.13.1-150600.13.6.1
corepack22 - update to 22.13.1-150600.13.6.1
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4
EasyApache - update to 4 25-4
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
nodejs-nodemon - update to 3.0.1-1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
npm - update to 10.8.2-1.20.18.2.1
npm - update to 10.8.2-1.20.18.2.1
v8-devel - update to 11.3.244.8-1.20.18.2.1
PowerProtect Data Manager - update to 19.19.0-15
nodejs-debuginfo - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs-libs - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-debugsource - update to 20.18.2-1
nodejs - update to 20.18.2-1
nodejs-devel - update to 20.18.2-1
nodejs-full-i18n - update to 20.18.2-1
nodejs-docs - update to 20.18.2-1
nodejs20 - addressed in versions 20.18.2-2.fc40, 20.18.2-2.fc41, 20.18.2-2.fc42
nodejs20-debugsource - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
npm20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-devel - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-debuginfo - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
corepack20 - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
nodejs20-docs - addressed in versions 20.18.2-150500.11.18.1, 20.18.2-150600.3.9.1
net-libs/nodejs - update to 22.13.1
nodejs22 - addressed in versions 22.13.1-1.fc41, 22.14.0-2.fc41
nodejs22-debugsource - update to 22.13.1-150600.13.6.1
nodejs22 - update to 22.13.1-150600.13.6.1
nodejs22-devel - update to 22.13.1-150600.13.6.1
npm22 - update to 22.13.1-150600.13.6.1
nodejs22-debuginfo - update to 22.13.1-150600.13.6.1
nodejs22-docs - update to 22.13.1-150600.13.6.1
corepack22 - update to 22.13.1-150600.13.6.1
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Fedora 41 update for nodejs22
- Fedora 42 update for nodejs20
- Fedora 41 update for nodejs20
- Fedora 40 update for nodejs20
- SUSE update for nodejs20
- SUSE update for nodejs20
- SUSE update for nodejs22
- EasyApache update for Node.js
- Red Hat Enterprise Linux 8 update for the nodejs:20 module
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Fedora 41 update for nodejs22
- openEuler 24.03 LTS SP1 update for nodejs
- openEuler 24.03 LTS update for nodejs
- Multiple vulnerabilities in IBM Business Automation Workflow
- Anolis OS update for nodejs:20 module
- Multiple vulnerabilities in Oracle GraalVM for JDK
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Gentoo update for Node.js