Path traversal in Node.js - CVE-2023-39332

 

Path traversal in Node.js - CVE-2023-39332

Published: October 17, 2023


Vulnerability identifier: #VU82068
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39332
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in paths stored in Uint8Array. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Node.js
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Fedora
IBM Cloud Transformation Advisor
EasyApache
Use Case Manager App
IBM Spectrum Control
IBM Business Automation Workflow
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
nodejs-nodemon
npm
nodejs20
nodejs-devel
nodejs-full-i18n
nodejs
nodejs-docs
net-libs/nodejs
nodejs-packaging
nodejs-packaging-bundler

How to mitigate CVE-2023-39332

Install update from vendor's website.

Node.js - update to 20.8.1
IBM Cloud Transformation Advisor - update to 3.8.0
EasyApache - update to 4 2023-10-18
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Answer Retrieval for Watson Discovery On Prem - update to 2.15.0
nodejs-nodemon - update to 3.0.1-1
Use Case Manager App - update to 4.0.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Spectrum Control - update to 5.4.11
npm - update to 10.8.1-1.20.16.0.1
nodejs20 - addressed in versions 20.8.1-1.fc37, 20.8.1-1.fc38, 20.8.1-1.fc39
nodejs-devel - update to 20.16.0-1
nodejs-full-i18n - update to 20.16.0-1
nodejs - update to 20.16.0-1
nodejs-docs - update to 20.16.0-1
net-libs/nodejs - update to 22.4.1
IBM Business Automation Workflow - update to 23.0.2
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4

External References

Related Security Bulletins