CVE-2024-36137

Public on 2024-07-09
Modified on 2024-07-09
Description
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.

Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
Severity
Low severity
Low
CVSS v3 Base Score
3.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2023 nodejs Not Affected
HAQM Linux 2023 nodejs20 2024-11-13 ALAS2023-2024-768 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
NVD CVSSv3 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N