CVE-2023-30590
Last modified
CVE-2023-30590 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: "Generates private and public Diffie-Hellman key values". The documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | >= 16.0.0, < 16.20.1 |
| Nodejs | Node.Js | >= 18.0.0, < 18.16.1 |
| Nodejs | Node.Js | >= 20.0.0, < 20.3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30590?
How severe is CVE-2023-30590?
How do I fix CVE-2023-30590?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30585A vulnerability has been identified in the Node.js (.msi ver…7.5
- CVE-2023-30586A privilege escalation vulnerability exists in Node.js 20 th…7.5
- CVE-2023-30587A vulnerability in Node.js version 20 allows for bypassing r…7.5
- CVE-2023-30588When an invalid public key is used to create an x509 certifi…5.3
- CVE-2023-30589The llhttp parser in the http module in Node v20.2.0 does no…7.5
- CVE-2023-3059A vulnerability, which was classified as critical, was found…9.8
- CVE-2023-30591Denial-of-service in NodeBB <= v2.8.10 allows unauthenticate…7.5
- CVE-2023-3060A vulnerability has been found in code-projects Agro-School …5.4
- CVE-2023-30601Privilege escalation when enabling FQL/Audit logs allows use…7.8
- CVE-2023-30602Hitron Technologies CODA-5310’s Telnet function transfers se…7.5
- CVE-2023-30603Hitron Technologies CODA-5310 Telnet function with the defau…9.8
- CVE-2023-30604It is identified a vulnerability of insufficient authenticat…9.8
Are you affected by CVE-2023-30590?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
