With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Feb 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 17 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhel Eus
|
|
CPEs | cpe:/a:redhat:rhel_eus:9.4 | |
Vendors & Products |
Redhat rhel Eus
|
Fri, 14 Feb 2025 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:enterprise_linux:9 |
Thu, 13 Feb 2025 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:8 | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
Thu, 06 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
ssvc
|
Thu, 23 Jan 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | nodejs: Node.js Worker Thread Exposure via Diagnostics Channel | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 22 Jan 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23. | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: hackerone
Published: 2025-01-22T01:11:30.802Z
Updated: 2025-02-28T13:07:33.161Z
Reserved: 2025-01-10T19:05:52.771Z
Link: CVE-2025-23083

Updated: 2025-02-28T13:07:33.161Z

Status : Awaiting Analysis
Published: 2025-01-22T02:15:33.930
Modified: 2025-02-28T13:15:28.213
Link: CVE-2025-23083
