CVE-2024-22018

v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

CVE-2024-22018

EPSS 0.00

Hodnocení závažnosti

2.9 CVSS 3.0 hackerone

útok z místního přístupu útok vyžaduje přípravu bez přihlášení bez zásahu uživatele
dopad únik části dat beze změny dat bez výpadku
přesah dopad jen na zranitelnou součást

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1 karet z 1 položek

1

CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Information published.

EPSS 0.00 CVE-2024-22018 Node.js US

Microsoft Security ·