Path traversal in Node.js - CVE-2023-39332
Published: October 17, 2023
Vulnerability identifier: #VU82068
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39332
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in paths stored in Uint8Array. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Node.js
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Fedora
IBM Cloud Transformation Advisor
EasyApache
Use Case Manager App
IBM Spectrum Control
IBM Business Automation Workflow
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
nodejs-nodemon
npm
nodejs20
nodejs-devel
nodejs-full-i18n
nodejs
nodejs-docs
net-libs/nodejs
nodejs-packaging
nodejs-packaging-bundler
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Fedora
IBM Cloud Transformation Advisor
EasyApache
Use Case Manager App
IBM Spectrum Control
IBM Business Automation Workflow
IBM Planning Analytics Workspace
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
nodejs-nodemon
npm
nodejs20
nodejs-devel
nodejs-full-i18n
nodejs
nodejs-docs
net-libs/nodejs
nodejs-packaging
nodejs-packaging-bundler
How to mitigate CVE-2023-39332
Install update from vendor's website.
Node.js - update to 20.8.1
IBM Cloud Transformation Advisor - update to 3.8.0
EasyApache - update to 4 2023-10-18
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Answer Retrieval for Watson Discovery On Prem - update to 2.15.0
nodejs-nodemon - update to 3.0.1-1
Use Case Manager App - update to 4.0.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Spectrum Control - update to 5.4.11
npm - update to 10.8.1-1.20.16.0.1
nodejs20 - addressed in versions 20.8.1-1.fc37, 20.8.1-1.fc38, 20.8.1-1.fc39
nodejs-devel - update to 20.16.0-1
nodejs-full-i18n - update to 20.16.0-1
nodejs - update to 20.16.0-1
nodejs-docs - update to 20.16.0-1
net-libs/nodejs - update to 22.4.1
IBM Business Automation Workflow - update to 23.0.2
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4
IBM Cloud Transformation Advisor - update to 3.8.0
EasyApache - update to 4 2023-10-18
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Answer Retrieval for Watson Discovery On Prem - update to 2.15.0
nodejs-nodemon - update to 3.0.1-1
Use Case Manager App - update to 4.0.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Spectrum Control - update to 5.4.11
npm - update to 10.8.1-1.20.16.0.1
nodejs20 - addressed in versions 20.8.1-1.fc37, 20.8.1-1.fc38, 20.8.1-1.fc39
nodejs-devel - update to 20.16.0-1
nodejs-full-i18n - update to 20.16.0-1
nodejs - update to 20.16.0-1
nodejs-docs - update to 20.16.0-1
net-libs/nodejs - update to 22.4.1
IBM Business Automation Workflow - update to 23.0.2
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Fedora 38 update for nodejs20
- Fedora 39 update for nodejs20
- Fedora 37 update for nodejs20
- Multiple vulnerabilities in cPanel EasyApache
- Red Hat Enterprise Linux 8 update for the nodejs:20 module
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM Business Automation Workflow Configuration Editor
- Multiple vulnerabilities in IBM Answer Retrieval for Watson Discovery
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Use Case Manager App
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Anolis OS update for nodejs:20 module
- Gentoo update for Node.js