Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9ccp-4gjg-264g

Опубликовано: 07 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the --allow-fs-read flag in Node.js 20. This flaw arises from a missing check in the fs.openAsBlob() API.

Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the --allow-fs-read flag in Node.js 20. This flaw arises from a missing check in the fs.openAsBlob() API.

Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

EPSS

Процентиль: 1%
0.00013
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 5.3
redhat
около 2 лет назад

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.5
nvd
11 месяцев назад

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.5
debian
11 месяцев назад

fs.openAsBlob() can bypass the experimental permission model when usin ...

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость метода fs.openAsBlob() программной платформы Node.js, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 1%
0.00013
Низкий

7.5 High

CVSS3

Дефекты

CWE-284