PT-2024-5138 · Node.Js+5 · Node.Js+5
4Xpl0R3R
·
Published
2024-04-19
·
Updated
2026-03-31
·
CVE-2024-36137
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Node.js (affected versions not specified)
Description:
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. The Node.js Permission Model does not operate on file descriptors; however, operations such as
fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file. This issue is related to shortcomings in access control.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Node.Js
Red Hat
Rocky Linux
Suse