Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36137

Опубликовано: 08 июл. 2024
Источник: redhat
CVSS3: 3.9
EPSS Низкий

Описание

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

A flaw was found in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. The Node.js Permission Model does not operate on file descriptors. However, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

Отчет

This vulnerability is specific to the Permission Model, which is currently an experimental feature of Node.js.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs20Fix deferred
Red Hat Enterprise Linux 8nodejs:18/nodejsNot affected
Red Hat Enterprise Linux 8nodejsFixedRHSA-2024:581426.08.2024
Red Hat Enterprise Linux 9nodejsFixedRHSA-2024:581526.08.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2299281nodejs: fs.fchown/fchmod bypasses permission model

EPSS

Процентиль: 23%
0.00076
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 года назад

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

CVSS3: 3.3
nvd
около 1 года назад

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

CVSS3: 3.3
debian
около 1 года назад

A vulnerability has been identified in Node.js, affecting users of the ...

CVSS3: 3.3
github
около 1 года назад

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

CVSS3: 3.9
fstec
больше 1 года назад

Уязвимость компонента Permission Model программной платформы Node.js, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 23%
0.00076
Низкий

3.9 Low

CVSS3