UBUNTU-CVE-2023-23920
Moderate
UBUNTU-CVE-2023-23920
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
Exploit probability
Not scored
Published
February 23, 2023
Required by
Not available
Last source change
April 22, 2026
02 / AFFECTED SOFTWARE
Affected packages
7 explicit affected versions
8 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
UBUNTU-CVE-2023-23920
View original source
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
05 / REFERENCES
Further evidence
- https://github.com/nodejs/node/commit/f369c0a739b9f0182ededa834a2a44e6fec322d1
- https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/
- https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/#node-js-insecure-loading-of-icu-data-through-icu_data-environment-variable-low-cve-2023-23920
- https://ubuntu.com/security/CVE-2023-23920
- https://ubuntu.com/security/notices/USN-6672-1
- https://www.cve.org/CVERecord?id=CVE-2023-23920