With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
History

Fri, 28 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
References

Mon, 17 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.4
Vendors & Products Redhat rhel Eus

Fri, 14 Feb 2025 03:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Thu, 13 Feb 2025 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

Thu, 06 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 13:30:00 +0000

Type Values Removed Values Added
Title nodejs: Node.js Worker Thread Exposure via Diagnostics Channel
Weaknesses CWE-863
References
Metrics threat_severity

None

threat_severity

Important


Wed, 22 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
Description With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.
References
Metrics cvssV3_0

{'score': 7.7, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2025-01-22T01:11:30.802Z

Updated: 2025-02-28T13:07:33.161Z

Reserved: 2025-01-10T19:05:52.771Z

Link: CVE-2025-23083

cve-icon Vulnrichment

Updated: 2025-02-28T13:07:33.161Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-22T02:15:33.930

Modified: 2025-02-28T13:15:28.213

Link: CVE-2025-23083

cve-icon Redhat

Severity : Important

Publid Date: 2025-01-22T01:11:30Z

Links: CVE-2025-23083 - Bugzilla