/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-39331

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-39331

CGA ID

CGA-p9q4-88hx-rwc6

Severity

7.5

High

CVSS V3

Description

A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations.

Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

References

  • https://images.chainguard.dev/security/CGA-p9q4-88hx-rwc6

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images