CVE-2015-0278: Fedoraproject Fedora
High severity, CVSS 10.0. EPSS: 3.2% chance of exploitation in the next 30 days.
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
Affected products
- Fedoraproject Fedora: version 21 only
- Libuv Project Libuv: up to and including 0.10.33
- Node.js Node.js: before 0.10.37 (fixed in 0.10.37)
Published 2015-05-18. Last modified 2026-06-17.