PT-2023-9687 · Node.Js · Node.Js

Rafaelgss

·

Publicado

2023-06-25

·

Atualizado

2024-12-16

·

CVE-2023-32005

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node.js version 20
Description A flaw in the experimental permission model of Node.js version 20 allows malicious actors to retrieve stats from files they do not have explicit read access to when the --allow-fs-read flag is used with a non-* argument. This issue arises from an inadequate permission model that fails to restrict file stats through the fs.statfs API.
Recommendations For Node.js version 20, consider disabling the experimental permission model or restricting the use of the fs.statfs API until a patch is available. Avoid using the --allow-fs-read flag with non-* arguments to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-09774
BIT-NODE-2023-32005
BIT-NODE-MIN-2023-32005
CVE-2023-32005
OPENSUSE-SU-2024:13117-1

Produtos afetados

Node.Js