First published: Mon Oct 16 2023(Updated: )
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to node's policy implementation, thus effectively disabling the integrity check. References: <a href="https://nodejs.org/en/blog/vulnerability/october-2023-security-releases">https://nodejs.org/en/blog/vulnerability/october-2023-security-releases</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Node.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2244415 is categorized as high due to the potential bypass of integrity checks.
To fix REDHAT-BUG-2244415, upgrade to the latest version of Node.js that includes the security patch addressing this vulnerability.
The risks associated with REDHAT-BUG-2244415 include the potential for attackers to disable integrity checks and compromise application security.
Versions of Node.js prior to the latest security update are affected by REDHAT-BUG-2244415.
The vulnerability REDHAT-BUG-2244415 was reported through Red Hat's bug tracking system and acknowledged by the Node.js team.