Bug 1187975 (CVE-2021-22921) - VUL-1: CVE-2021-22921: nodejs10,nodejs12,nodejs14,nodejs: Windows installer - Node Installer Local Privilege Escalation
Summary: VUL-1: CVE-2021-22921: nodejs10,nodejs12,nodejs14,nodejs: Windows installer -...
Status: RESOLVED INVALID
Alias: CVE-2021-22921
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Adam Majer
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-07-02 13:58 UTC by Robert Frohl
Modified: 2021-07-02 13:58 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-07-02 13:58:12 UTC
Windows installer - Node Installer Local Privilege Escalation (Medium) (CVE-2021-22921)

Node.js is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

You can read more about it in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22921

Impacts:

    All versions of the 16.x, 14.x, and 12.x releases lines

https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/
Comment 1 Robert Frohl 2021-07-02 13:58:34 UTC
not relevant for linux, closing