CVE-2024-22020
概要

A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.

公表日 2024年7月9日11:15
登録日 2024年7月9日16:00
最終更新日 2024年11月22日21:15
関連情報、対策とツール
共通脆弱性一覧