Back to overview

CVE-2022-24783

CRITICAL
10.0
CVSS 3.1
Description
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect users of Deno Deploy. The vulnerability has been patched in Deno 1.20.3. There is no workaround. All users are recommended to upgrade to 1.20.3 immediately.

Metadata

CVE ID
CVE-2022-24783
State
PUBLISHED
Assigner
GitHub_M
Reserved
2022-02-10 00:00 UTC
Published
2022-03-25 21:15 UTC
Last updated
2025-04-23 18:43 UTC
Primary CWE
CWE-269
CWE-269: Improper Privilege Management
Vendor / Product
denoland / deno
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
denoland deno >= 1.18.0, < 1.20.3
Weakness (CWE)
CWESourceDescription
CWE-269 cna CWE-269: Improper Privilege Management
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview