CRITICAL 9.8 Microsoft
CVE-2024-21896
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals namely Buffer.prototype.utf8Write the application can modify the result of path.resolve() which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.
Microsoft Security Update 2024-Feb: The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals namely Buffer.prototype.utf8Write the application can modify the result of path.resolve() which leads to a path traversal vulnerability.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.
Affected Products
- azl3 nodejs 20.14.0-1 on Azure Linux 3.0
- azl3 nodejs 20.10.0-2 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21896
- https://nvd.nist.gov/vuln/detail/CVE-2024-21896
This critical severity vulnerability with a CVSS score of 9.8 was published on 2024-02-13 via Microsoft. Affected: azl3 nodejs 20.14.0-1 on Azure Linux 3.0, azl3 nodejs 20.10.0-2 on Azure Linux 3.0.
Risk Timeline
CVE Disclosed2024-02-13 · 954 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21896NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2024-21896Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/ne | CRITICAL | 10.0 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x | CRITICAL | 10.0 |
| CVE-2025-32433 PoC | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE | CRITICAL | 10.0 |
| CVE-2025-62168 PoC | Squid vulnerable to information disclosure via authentication credential leakage | CRITICAL | 10.0 |
| CVE-2026-7374 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via sy | CRITICAL | 9.9 |
vulnfeed aggregates 11940 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.