LOW 2.9 Microsoft
CVE-2024-22018
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Microsoft Security Update 2024-Jul: A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Affected Products
- azl3 nodejs 20.14.0-9 on Azure Linux 3.0
- azl3 nodejs 20.14.0-10 on Azure Linux 3.0
- azl3 nodejs 20.14.0-14 on Azure Linux 3.0
- azl3 nodejs 20.14.0-13 on Azure Linux 3.0
- azl3 nodejs 20.14.0-15 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-22018
- https://nvd.nist.gov/vuln/detail/CVE-2024-22018
This low severity vulnerability with a CVSS score of 2.9 was published on 2024-07-09 via Microsoft. Affected: azl3 nodejs 20.14.0-9 on Azure Linux 3.0, azl3 nodejs 20.14.0-10 on Azure Linux 3.0, azl3 nodejs 20.14.0-14 on Azure Linux 3.0 and 2 more.
vulnfeed aggregates 10103 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.