CVE-2023-33966
published 2023-05-31CVE-2023-33966: Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.63%
48.6th percentile
Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too. Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected. This problem has been patched in Deno v1.34.1 and deno_runtime 0.114.1 and all users are recommended to update to this version. No workaround is available for this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | — | — |
| deno | deno | >= 1.34.0 < 1.34.1 | 1.34.1 |
| deno | deno_runtime | — | — |
| deno | deno_runtime | >= 0.114.0 < 0.115.0 | 0.115.0 |
| denoland | deno | — | — |
| denoland | deno | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Missing "--allow-net" permission check for built-in Node modules
osv·2023-05-31
CVE-2023-33966 [HIGH] Missing "--allow-net" permission check for built-in Node modules
Missing "--allow-net" permission check for built-in Node modules
### Impact
Outbound HTTP requests made using the built-in "node:http" or "node:https" modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too.
Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected.
### Patches
This problem has been patched in Deno v1.34.1 and all users are recommended to update to this version.
### Workarounds
No workaround is available for this issue.
GHSA
Missing "--allow-net" permission check for built-in Node modules
ghsa·2023-05-31
CVE-2023-33966 [HIGH] CWE-269 Missing "--allow-net" permission check for built-in Node modules
Missing "--allow-net" permission check for built-in Node modules
### Impact
Outbound HTTP requests made using the built-in "node:http" or "node:https" modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too.
Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected.
### Patches
This problem has been patched in Deno v1.34.1 and all users are recommended to update to this version.
### Workarounds
No workaround is available for this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-31
Published