Количество 7
Количество 7
BDU:2026-00544
Уязвимость функции futimes() программной платформы Node.js, позволяющая нарушителю получить доступ на изменение файлов
CVE-2025-55132
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
CVE-2025-55132
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
CVE-2025-55132
A flaw in Node.js's permission model allows a file's access and modifi ...
GHSA-pm9v-wcw9-xgpv
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.
SUSE-SU-2026:0301-1
Security update for nodejs22
SUSE-SU-2026:0295-1
Security update for nodejs22
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-00544 Уязвимость функции futimes() программной платформы Node.js, позволяющая нарушителю получить доступ на изменение файлов | CVSS3: 3.3 | 0% Низкий | 22 дня назад | |
CVE-2025-55132 A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25. | CVSS3: 2.8 | 0% Низкий | 15 дней назад | |
CVE-2025-55132 A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25. | CVSS3: 2.8 | 0% Низкий | 15 дней назад | |
CVE-2025-55132 A flaw in Node.js's permission model allows a file's access and modifi ... | CVSS3: 2.8 | 0% Низкий | 15 дней назад | |
GHSA-pm9v-wcw9-xgpv A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25. | CVSS3: 2.8 | 0% Низкий | 14 дней назад | |
SUSE-SU-2026:0301-1 Security update for nodejs22 | 8 дней назад | |||
SUSE-SU-2026:0295-1 Security update for nodejs22 | 9 дней назад |
Уязвимостей на страницу