Bypass Policy Mechanism in Node.js Affecting Multiple Versions
CVE-2023-32006
8.8HIGH
What is CVE-2023-32006?
This vulnerability arises from the module.constructor.createRequire()
function, enabling unauthorized access to modules outside of the defined policy.json restrictions. It poses a risk for users leveraging the experimental policy feature in Node.js, potentially leading to unregulated module loading and other security concerns across versions 16.x, 18.x, and 20.x.
Affected Version(s)
Node 4.0 < 4.*
Node 5.0 < 5.*
Node 6.0 < 6.*