Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-37372

Опубликовано: 09 янв. 2025
Источник: redhat
CVSS3: 3.6

Описание

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

A flaw was found in Node.js. The Permission Model assumes that any UNC path starting with two backslashes \\ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

Отчет

This vulnerability affects Windows users of the Node.js Permission Model in version v22.x and v20.x. No Red Hat products are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Not affected
Red Hat Enterprise Linux 8nodejs:18/nodejsNot affected
Red Hat Enterprise Linux 8nodejs:20/nodejsNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-754
https://bugzilla.redhat.com/show_bug.cgi?id=2336663nodejs: Permission model improperly processes UNC paths

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
10 месяцев назад

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

CVSS3: 3.6
nvd
10 месяцев назад

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

CVSS3: 3.6
debian
10 месяцев назад

The Permission Model assumes that any path starting with two backslash ...

CVSS3: 3.6
github
10 месяцев назад

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость компонента Permission Model программной платформы Node.js, позволяющая нарушителю оказать воздействие на целостность данных

3.6 Low

CVSS3