A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file stats through the `fs.statfs` API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
References
Link Resource
https://hackerone.com/reports/2051224 Exploit Third Party Advisory
https://security.netapp.com/advisory/ntap-20231103-0004/ Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2023-09-12T01:36:55.851Z

Updated: 2023-09-12T01:36:55.851Z

Reserved: 2023-05-01T01:00:12.220Z


Link: CVE-2023-32005

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-12T02:15:11.863

Modified: 2023-12-22T17:07:29.110


Link: CVE-2023-32005

JSON object: View

cve-icon Redhat Information

No data.

CWE