Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-37372

Опубликовано: 09 янв. 2025
Источник: redhat
CVSS3: 3.6
EPSS Низкий

Описание

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

A flaw was found in Node.js. The Permission Model assumes that any UNC path starting with two backslashes \\ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

Отчет

This vulnerability affects Windows users of the Node.js Permission Model in version v22.x and v20.x. No Red Hat products are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Not affected
Red Hat Enterprise Linux 8nodejs:18/nodejsNot affected
Red Hat Enterprise Linux 8nodejs:20/nodejsNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-754
https://bugzilla.redhat.com/show_bug.cgi?id=2336663nodejs: Permission model improperly processes UNC paths

EPSS

Процентиль: 0%
0.00006
Низкий

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
7 месяцев назад

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

CVSS3: 3.6
nvd
7 месяцев назад

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

CVSS3: 3.6
debian
7 месяцев назад

The Permission Model assumes that any path starting with two backslash ...

CVSS3: 3.6
github
7 месяцев назад

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость компонента Permission Model программной платформы Node.js, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 0%
0.00006
Низкий

3.6 Low

CVSS3