[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Privilege escalation vulnerability in Node.js - CVE-2024-22017

ID: oval:org.secpod.oval:def:99965Date: (C)2024-05-10   (M)2024-05-10
Class: VULNERABILITYFamily: macos




The host is installed with Node.js 18.x before 18.19.1, 20.x before 20.11.1, or 21.x before 21.6.2 and is prone to a privilege escalation vulnerability. A flaw is present in the application which fails to handle setuid(). Successful exploitation allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid().

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Apple Mac OS X 10.15
Apple Mac OS 11
Apple Mac OS 12
Product:
Node.js
Reference:
CVE-2024-22017
CVE    1
CVE-2024-22017

© SecPod Technologies