When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check.
Impacts:
This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x.
Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: hackerone
Published: 2023-10-18T03:55:18.483Z
Updated: 2023-10-18T03:55:18.483Z
Reserved: 2023-07-20T01:00:12.444Z
Link: CVE-2023-38552
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-18T04:15:11.200
Modified: 2024-02-16T17:11:52.637
Link: CVE-2023-38552
JSON object: View
Redhat Information
No data.
CWE