cbcvebase.
CVE-2023-32004
published 2023-08-15

CVE-2023-32004: A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of…

PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.82%
76.3th percentile
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiannodejs
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm81:2.7.4-0ubuntu1.10+esm8
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm11:2.17.1-1ubuntu0.18+esm1
nodejsnode>= 10.0 < 10.*10.*
nodejsnode>= 11.0 < 11.*11.*
nodejsnode>= 12.0 < 12.*12.*
nodejsnode>= 13.0 < 13.*13.*
nodejsnode>= 14.0 < 14.*14.*
nodejsnode>= 15.0 < 15.*15.*
nodejsnode>= 17.0 < 17.*17.*
nodejsnode>= 19.0 < 19.*19.*
nodejsnode>= 20.0 < 20.5.120.5.1
nodejsnode>= 4.0 < 4.*4.*
nodejsnode>= 5.0 < 5.*5.*
nodejsnode>= 6.0 < 6.*6.*
nodejsnode>= 7.0 < 7.*7.*
nodejsnode>= 8.0 < 8.*8.*
nodejsnode>= 9.0 < 9.*9.*
nodejsnode.js>= 20.0.0 < 20.8.020.8.0
nodejsnode.js20.0.0 – 20.5.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv2.2LOW
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.