CVE-2024-22018
published 2024-07-10CVE-2024-22018: A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises…
PriorityP410low2.9CVSS 3.0
AVLACHPRNUINSUCLINAN
EPSS
0.46%
37.3th percentile
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 20.15.1+dfsg-1 (forky) | nodejs 20.15.1+dfsg-1 (forky) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | >= 20.0 < 20.15.1 | 20.15.1 |
| nodejs | node | >= 21.0 < 21.* | 21.* |
| nodejs | node | >= 22.0 < 22.4.1 | 22.4.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1-r0 | 20.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.15.1+dfsg-1 | 20.15.1+dfsg-1 |
CVSS provenance
nvdv3.02.9LOWCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
osv2.9LOW
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-22018: A vulnerability has been identified in Node
osv·2024-07-10·CVSS 2.9
CVE-2024-22018 [LOW] CVE-2024-22018: A vulnerability has been identified in Node
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
OSV
CVE-2024-22018: A vulnerability has been identified in Node
osv·2024-07-10·CVSS 2.9
CVE-2024-22018 [LOW] CVE-2024-22018: A vulnerability has been identified in Node
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
GHSA
GHSA-9xvm-xmw3-2hm2: A vulnerability has been identified in Node
ghsa_unreviewed·2024-07-10
CVE-2024-22018 [LOW] GHSA-9xvm-xmw3-2hm2: A vulnerability has been identified in Node
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Red Hat
nodejs: fs.lstat bypasses permission model
vendor_redhat·2024-07-10·CVSS 2.9
CVE-2024-22018 [LOW] nodejs: fs.lstat bypasses permission model
nodejs: fs.lstat bypasses permission model
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
A flaw was found in the Node.js package. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious a
Debian
CVE-2024-22018: nodejs - A vulnerability has been identified in Node.js, affecting users of the experimen...
vendor_debian·2024·CVSS 2.9
CVE-2024-22018 [LOW] CVE-2024-22018: nodejs - A vulnerability has been identified in Node.js, affecting users of the experimen...
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 20.15.1+dfsg-1)
sid: resolved (fixed in 20.15.1+dfsg-1)
trixie: resolved (fixed in 20.15.1+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/07/11/6http://www.openwall.com/lists/oss-security/2024/07/19/3https://hackerone.com/reports/2145862http://www.openwall.com/lists/oss-security/2024/07/11/6http://www.openwall.com/lists/oss-security/2024/07/19/3https://hackerone.com/reports/2145862https://security.netapp.com/advisory/ntap-20240816-0007/
2024-07-10
Published