CVE-2024-37372
published 2025-01-09CVE-2024-37372: The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This…
PriorityP412low3.6CVSS 3.0
AVLACHPRNUIRSUCLILAN
EPSS
0.49%
40.0th percentile
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | — | — |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | >= 20.0 < 20.15.1 | 20.15.1 |
| nodejs | node | >= 21.0 < 21.* | 21.* |
| nodejs | node | >= 22.0 < 22.4.1 | 22.4.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | nodejs | >= 0 < 0 | 0 |
| nodejs | nodejs | >= 0 < 0 | 0 |
| nodejs | nodejs | >= 0 < 0 | 0 |
| nodejs | nodejs | >= 0 < 0 | 0 |
| nodejs | nodejs | >= 0 < 0 | 0 |
CVSS provenance
nvdv3.03.6LOWCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs: Permission model improperly processes UNC paths
vendor_redhat·2025-01-09·CVSS 3.6
CVE-2024-37372 [LOW] CWE-754 nodejs: Permission model improperly processes UNC paths
nodejs: Permission model improperly processes UNC paths
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
A flaw was found in Node.js. The Permission Model assumes that any UNC path starting with two backslashes `\\` has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
Statement: This vulnerability affects Windows users of the Node.js Permission Model in version v22.x and v20.x. No Red Hat products are affected.
Package: nodejs22 (Red Hat Enterprise Linux 10) - Not affected
Package: nodejs:18/nodejs (Red Hat Enterprise Linux 8) - Not affected
Package: nodejs:20/nodejs (
Debian
CVE-2024-37372: nodejs - The Permission Model assumes that any path starting with two backslashes \ has a...
vendor_debian·2024·CVSS 3.6
CVE-2024-37372 [LOW] CVE-2024-37372: nodejs - The Permission Model assumes that any path starting with two backslashes \ has a...
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
CVE-2024-37372: The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true
osv·2025-01-09·CVSS 3.6
CVE-2024-37372 [LOW] CVE-2024-37372: The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
GHSA
GHSA-7975-2qr9-g542: The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true
ghsa_unreviewed·2025-01-09
CVE-2024-37372 [LOW] CWE-22 GHSA-7975-2qr9-g542: The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-09
Published