Site icon TheCyberThrone

Node.Js Fixes Multiple Vulnerabilities -CVE-2024-27980

Advertisements

The Node.js Project has released a security update to address multiple vulnerabilities, including a high-severity flaw that could allow attackers to bypass security measures and execute arbitrary code.

The most severe vulnerability, CVE-2024-36138, is a bypass of an incomplete fix for a previous issue, CVE-2024-27980, dubbed the BatBadBut vulnerability. This flaw could allow attackers to inject and execute arbitrary commands on Windows systems, even when shell options are disabled. This vulnerability affects all active Node.js release lines (v18.x, v20.x, and v22.x) and poses a significant risk to Windows users.

Advertisements

In addition to the high-severity CVE-2024-36138 vulnerability, the update addresses several medium and low-severity vulnerabilities as below.

These vulnerabilities affect all users of the specified Node.js versions, particularly those using Windows systems and the experimental permission model.

The Node.js Project strongly recommends that all users upgrade to the latest versions immediately. It is crucial for users to take immediate action to protect their systems and data.

Exit mobile version