vulnerability
Alpine Linux: CVE-2023-39331: Path Traversal
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:N) | Oct 18, 2023 | Mar 21, 2024 | Dec 22, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:N)
Published
Oct 18, 2023
Added
Mar 21, 2024
Modified
Dec 22, 2025
Description
A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Solutions
alpine-linux-upgrade-nodejs-currentalpine-linux-upgrade-nodejs
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.