Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 28

Количество 28

github логотип

GHSA-pm9v-wcw9-xgpv

6 месяцев назад

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 2.8
EPSS: Низкий
ubuntu логотип

CVE-2025-55132

6 месяцев назад

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-55132

6 месяцев назад

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-55132

6 месяцев назад

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-55132

6 месяцев назад

A flaw in Node.js's permission model allows a file's access and modifi ...

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2026-00544

7 месяцев назад

Уязвимость функции futimes() программной платформы Node.js, позволяющая нарушителю получить доступ на изменение файлов

CVSS3: 3.3
EPSS: Низкий
redos логотип

ROS-20260417-73-0032

4 месяца назад

Уязвимость nodejs

CVSS3: 3.3
EPSS: Низкий
rocky логотип

RLSA-2026:2783

5 месяцев назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2782

5 месяцев назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2781

5 месяцев назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2422

6 месяцев назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2421

6 месяцев назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2420

6 месяцев назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1843

6 месяцев назад

Important: nodejs22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1842

6 месяцев назад

Important: nodejs24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2783

5 месяцев назад

ELSA-2026-2783: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2782

5 месяцев назад

ELSA-2026-2782: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2781

5 месяцев назад

ELSA-2026-2781: nodejs:24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2422

6 месяцев назад

ELSA-2026-2422: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2421

6 месяцев назад

ELSA-2026-2421: nodejs:22 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pm9v-wcw9-xgpv

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 2.8
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-55132

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-55132

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-55132

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-55132

A flaw in Node.js's permission model allows a file's access and modifi ...

CVSS3: 5.3
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-00544

Уязвимость функции futimes() программной платформы Node.js, позволяющая нарушителю получить доступ на изменение файлов

CVSS3: 3.3
0%
Низкий
7 месяцев назад
redos логотип
ROS-20260417-73-0032

Уязвимость nodejs

CVSS3: 3.3
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:2783

Important: nodejs:20 security update

5 месяцев назад
rocky логотип
RLSA-2026:2782

Important: nodejs:22 security update

5 месяцев назад
rocky логотип
RLSA-2026:2781

Important: nodejs:24 security update

5 месяцев назад
rocky логотип
RLSA-2026:2422

Important: nodejs:20 security update

6 месяцев назад
rocky логотип
RLSA-2026:2421

Important: nodejs:22 security update

6 месяцев назад
rocky логотип
RLSA-2026:2420

Important: nodejs:24 security update

6 месяцев назад
rocky логотип
RLSA-2026:1843

Important: nodejs22 security update

6 месяцев назад
rocky логотип
RLSA-2026:1842

Important: nodejs24 security update

6 месяцев назад
oracle-oval логотип
ELSA-2026-2783

ELSA-2026-2783: nodejs:20 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-2782

ELSA-2026-2782: nodejs:22 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-2781

ELSA-2026-2781: nodejs:24 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-2422

ELSA-2026-2422: nodejs:20 security update (IMPORTANT)

6 месяцев назад
oracle-oval логотип
ELSA-2026-2421

ELSA-2026-2421: nodejs:22 security update (IMPORTANT)

6 месяцев назад

Уязвимостей на страницу