Skip to content

Commit

Permalink
security/vuxml: remove duplicated entry, see 3bac9fe
Browse files Browse the repository at this point in the history
Reported by:	flo@smeets.xyz
  • Loading branch information
mfechner committed Mar 18, 2024
1 parent 576c9fe commit 7ad6e0e
Showing 1 changed file with 0 additions and 33 deletions.
33 changes: 0 additions & 33 deletions security/vuxml/vuln/2024.xml
Original file line number Diff line number Diff line change
Expand Up @@ -481,39 +481,6 @@
</dates>
</vuln>

<vuln vid="46a9eb0f-d7d2-11ee-bb12-001b217b3468">
<topic>null -- null</topic>
<affects>
<package>
<name>null</name>
<range><lt>null</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>support@hackerone.com reports:</p>
<blockquote cite="https://hackerone.com/reports/2237545">
<p>On Linux, Node.js ignores certain environment variables if those
may have been set by an unprivileged user while the process is
running with elevated privileges with the only exception of
CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this
exception, Node.js incorrectly applies this exception even when
certain other capabilities have been set. This allows unprivileged
users to inject code that inherits the process&apos;s elevated
privileges.</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2024-21892</cvename>
<url>https://nvd.nist.gov/vuln/detail/CVE-2024-21892</url>
</references>
<dates>
<discovery>2024-02-20</discovery>
<entry>2024-03-01</entry>
</dates>
</vuln>

<vuln vid="3567456a-6b17-41f7-ba7f-5cd3efb2b7c9">
<topic>electron{27,28} -- Use after free in Mojo</topic>
<affects>
Expand Down

0 comments on commit 7ad6e0e

Please sign in to comment.