Aller au contenu

Fiche vulnérabilité

CVE-2024-21892 : faille élevée nodejs node.js (CVSS 7.8)

Description

On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this exception, Node.js incorrectly applies this exception even when certain other capabilities have been set. This allows unprivileged users to inject code that inherits the process's elevated privileges.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 févr. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • nodejs node.js

Références

Rechercher une autre vulnérabilité dans la base CVE