First published: Fri Feb 16 2024(Updated: )
Node.js could allow a local authenticated attacker to gain elevated privileges on the system, caused by a bug in the implementation of the exception of CAP_NET_BIND_SERVICE. An attacker could exploit this vulnerability to inject code that inherits the process's elevated privileges.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/node | <18.19.1 | 18.19.1 |
redhat/node | <20.11.1 | 20.11.1 |
redhat/node | <21.6.2 | 21.6.2 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.