Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect users of Deno Deploy. The vulnerability has been patched in Deno 1.20.3. There is no workaround. All users are recommended to upgrade to 1.20.3 immediately.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-03-25T21:15:12.000Z
Updated: 2025-04-23T18:43:31.886Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24783

Updated: 2024-08-03T04:20:50.451Z

Status : Modified
Published: 2022-03-25T22:15:08.093
Modified: 2024-11-21T06:51:05.240
Link: CVE-2022-24783

No data.