CVE-2023-39333
Last modified
CVE-2023-39333 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. This vulnerability affects users of any active release line of Node.js. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. This vulnerability affects users of any active release line of Node.js. The vulnerable feature is only available if Node.js is started with the `--experimental-wasm-modules` command line option.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-39333?
How severe is CVE-2023-39333?
How do I fix CVE-2023-39333?
Are you affected by CVE-2023-39333?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
