First published: Mon Oct 16 2023(Updated: )
A previously disclosed vulnerability (<a href="https://access.redhat.com/security/cve/CVE-2023-30584">CVE-2023-30584</a>) was patched insufficiently. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations. References: <a href="https://nodejs.org/en/blog/vulnerability/october-2023-security-releases">https://nodejs.org/en/blog/vulnerability/october-2023-security-releases</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Node.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2244413 is categorized as high due to the potential for path traversal exploits affecting the application.
To fix REDHAT-BUG-2244413, you should update your Node.js version to the latest release that contains the security patch.
REDHAT-BUG-2244413 specifically affects Node.js and its related components.
Currently, there is no known workaround for REDHAT-BUG-2244413, and updating is recommended.
REDHAT-BUG-2244413 was disclosed as a new vulnerability in October 2023.