CVE-2023-23920
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js includes ICU (International Components for Unicode), the library behind its Intl APIs, string collation, date and number formatting, and other locale-sensitive behavior. ICU's behavior is driven by a data file, and by default ICU lets the ICU_DATA environment variable point it at a different data directory.
A vulnerability (CVE-2023-23920) has been identified in how Node.js builds ICU. Because Node.js left ICU's user data override enabled, a Node.js process would search the location named by ICU_DATA and potentially load ICU data from it, even when running with elevated privileges. A local attacker who can set the environment of a privileged Node.js process can therefore make it load attacker-controlled ICU data.
This flaw maps to CWE-426 (Untrusted Search Path), where software looks for resources in a location that an attacker may control. ICU's lookup of ICU_DATA happened inside the library, independently of how Node.js itself treats its environment, so a privileged process could thus have its locale and text-processing data replaced by an unprivileged user.
Exploitation is local and narrow: the target must be a Node.js process running with elevated privileges, for example through setuid, and the attacker must be able to set its environment and supply a crafted ICU data file. NVD rates the integrity impact as high, since the loaded data changes how the process formats, compares and transforms text; Node.js rated the issue Low. This issue affects every Node.js release line from 4.x through 19.x up to the versions listed above.
Details
Module Info
- Product: Node.js
- Affected packages: node (bundles ICU under deps/icu-small)
- Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
- Fixed in: Node.js 14.21.3, 16.19.1, 18.14.1 and 19.6.1 (all February 16, 2023), the Node.js February 2023 security releases; Node.js NES v12.22.18 (12.x line, shipped April 28, 2026), which brings the fix to the 12.x line, which never received it upstream. The other release lines listed above never received a fix
Vulnerability Info
This Medium-severity vulnerability is found in the Node.js build configuration for its bundled ICU library. NVD assigns a CVSS v3.1 score of 4.2; the Node.js project rated it Low in its security release.
ICU reads its data either from the copy compiled into the program or from a data directory, and unless it is built with ICU_NO_USER_DATA_OVERRIDE, it honors the ICU_DATA environment variable as a place to look for that data. In the vulnerable versions, Node.js's configure script did not set that option, so ICU consulted ICU_DATA in every Node.js process, privileged or not. The fix adds ICU_NO_USER_DATA_OVERRIDE to the build defines, so ICU no longer lets the environment redirect its data lookup. See the Node.js fix commit for the exact change.
An attacker with a local account who can start, or set the environment of, a Node.js process that runs with more privileges than the attacker has could point ICU_DATA at a directory they control. The privileged process would then use the attacker's ICU data for its locale-sensitive operations, which can change the results of formatting, comparison and other text processing that the program relies on.
Note: Node.js processes that run with the same privileges as the user who starts them gain nothing from this issue, since that user could already control the process. The --icu-data-dir option and the NODE_ICU_DATA environment variable are Node.js's own mechanisms for selecting ICU data and are not what this CVE describes.
Mitigation
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which include this fix.
- Where an upgrade is not yet possible, avoid running Node.js with elevated privileges, and clear ICU_DATA from the environment of any privileged Node.js process.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.
Credits
- Ben Noordhuis (reporter)
- Rafael Gonzaga (remediation developer)