CVE-2024-22020
published 2024-07-09CVE-2024-22020: A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary…
PriorityP434medium6.5CVSS 3.0
AVLACHPRNUIRSUCLIHAH
EPSS
1.10%
62.4th percentile
A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 18.20.4+dfsg-1~deb12u1 (bookworm) | nodejs 18.20.4+dfsg-1~deb12u1 (bookworm) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 18.0 < 18.20.4 | 18.20.4 |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | >= 20.0 < 20.15.1 | 20.15.1 |
| nodejs | node | >= 21.0 < 21.* | 21.* |
| nodejs | node | >= 22.0 < 22.4.1 | 22.4.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
osv6.5MEDIUM
vendor_redhat7.8HIGH
vendor_oracle7.1MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-22020: A security flaw in Node
osv·2024-07-09·CVSS 6.5
CVE-2024-22020 [MEDIUM] CVE-2024-22020: A security flaw in Node
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.
GHSA
GHSA-ch4x-f5c4-36gv: A security flaw in Node
ghsa_unreviewed·2024-07-09
CVE-2024-22020 [MEDIUM] CWE-284 GHSA-ch4x-f5c4-36gv: A security flaw in Node
A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.
OSV
CVE-2024-22020: A security flaw in Node
osv·2024-07-09·CVSS 6.5
CVE-2024-22020 [MEDIUM] CVE-2024-22020: A security flaw in Node
A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.
Red Hat
kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
vendor_redhat·2025-04-16·CVSS 7.8
CVE-2025-22020 [HIGH] CWE-416 kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
In the Linux kernel, the following vulnerability has been resolved:
memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
This fixes the following crash:
BUG: KASAN: slab-use-after-free in rtsx_usb_ms_poll_card+0x159/0x200 [rtsx_usb_ms]
Read of size 8 at addr ffff888136335380 by task kworker/6:0/140241
CPU: 6 UID: 0 PID: 140241 Comm: kworker/6:0 Kdump: loaded Tainted: G E 6.14.0-rc6+ #1
Tainted: [E]=UNSIGNED_MODULE
Hardware name: LENOVO 30FNA1V7CW/1057, BIOS S0EKT54A 07/01/2024
Workqueue: events rtsx_usb_ms_poll_card [rtsx_usb_ms]
Call Trace:
dump_stack_lvl+0x51/0x70
print_address_description.constprop.0+0x27/0x320
? rtsx_usb_ms_poll_card+0x159/0x200 [rtsx_usb_ms]
print_report+0x3e/0x70
ka
Oracle
Oracle Oracle PeopleSoft Risk Matrix: OpenSearch (Node.js) — CVE-2024-22020
vendor_oracle·2025-01-15·CVSS 6.5
CVE-2024-22020 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: OpenSearch (Node.js) — CVE-2024-22020
Oracle Oracle PeopleSoft Risk Matrix: OpenSearch (Node.js) vulnerability
CVE: CVE-2024-22020
CVSS: 6.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: Blockchain Cloud Service Console (Node.js) — CVE-2024-22020
vendor_oracle·2024-10-15·CVSS 7.1
CVE-2024-22020 [MEDIUM] Oracle Oracle Blockchain Platform Risk Matrix: Blockchain Cloud Service Console (Node.js) — CVE-2024-22020
Oracle Oracle Blockchain Platform Risk Matrix: Blockchain Cloud Service Console (Node.js) vulnerability
CVE: CVE-2024-22020
CVSS: 7.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
nodejs: Bypass network import restriction via data URL
vendor_redhat·2024-07-09·CVSS 6.5
CVE-2024-22020 [MEDIUM] nodejs: Bypass network import restriction via data URL
nodejs: Bypass network import restriction via data URL
A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.
A flaw was found in the Node.js package. By embedding non-network imports in data URLs, this flaw allows an attacker to execute arbitrary code, compromising system security.
Statement: This vulnerability is categorized as moderate severity rather than high due to its specific conditions for exploitation and impact scope. While the flaw permits
Debian
CVE-2024-22020: nodejs - A security flaw in Node.js allows a bypass of network import restrictions. By e...
vendor_debian·2024·CVSS 6.5
CVE-2024-22020 [MEDIUM] CVE-2024-22020: nodejs - A security flaw in Node.js allows a bypass of network import restrictions. By e...
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.
Scope: local
bookworm: resolved (fixed in 18.20.4+dfsg-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 20.15.1+dfsg-1)
sid: resolved (fixed in 20.15.1+dfsg-1)
trixie: resolved (fixed in 20.15.1+dfsg-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/07/11/6http://www.openwall.com/lists/oss-security/2024/07/19/3https://hackerone.com/reports/2092749http://www.openwall.com/lists/oss-security/2024/07/11/6http://www.openwall.com/lists/oss-security/2024/07/19/3https://hackerone.com/reports/2092749https://security.netapp.com/advisory/ntap-20241122-0006/
2024-07-09
Published