Skip to content

Commit

Permalink
Update locale/en/blog/vulnerability/february-2023-security-releases.md
Browse files Browse the repository at this point in the history
Signed-off-by: Michael Dawson <mdawson@devrus.com>
  • Loading branch information
mhdawson committed Feb 16, 2023
1 parent fad3ed0 commit 57ce43f
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,7 @@ Impacts:

* All versions of the 19.x, 18.x, and 16.x release lines.

## Node.js insecure loading of ICU data through ICU_DATA environment variable (Low) ([CVE-2023-23920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23920))
## Node.js insecure loading of ICU data through ICU_DATA environment variable (Low) ([CVE-2023-23920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23920))

Node.js would search and potentially load ICU data when running with elevated priviledges. Node.js
was modified to build with ICU_NO_USER_DATA_OVERRIDE to avoid this.
Expand Down

0 comments on commit 57ce43f

Please sign in to comment.