CVE-2024-22017
HIGH7.3EPSS 0.88%發布日:2024/11/29修改日:2026/2/11
描述
setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.
受影響套件(2)
- Bitnami/node>= 20.0.0, < 20.11.1, >= 21.0.0, < 21.6.2
- Bitnami/node-min>= 20.0.0, < 20.11.1, >= 21.0.0, < 21.6.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L |
參考連結(7)
- WEBhttps://github.com/nodejs/node/releases/tag/v20.11.1
- WEBhttps://github.com/nodejs/node/releases/tag/v21.6.2
- WEBhttps://hackerone.com/reports/2170226
- WEBhttps://nodejs.org/en/blog/vulnerability/february-2024-security-releases#setuid-does-not-drop-all-privileges-due-to-io_uring-cve-2024-22017---high
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2024-22017
- WEBhttps://security.netapp.com/advisory/ntap-20240517-0007/
- WEBhttp://www.openwall.com/lists/oss-security/2024/03/11/1