Home / CVE DB / CVE-2024-22018
Standard
Vulnerability Identifier

CVE-2024-22018

2024-07-10
Severity Assessment
LOW
CVSS v3.x Score
Clinical Analysis (Description)

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Vector Sequencing

Attack Parameters

Impact Consequences

Technical Impact

Timeline

Time Line

PUBLICATION
10 Jul 2024
MODIFICATION
21 Nov 2024
FIRST PATCH
21 Jan 2025
Impact Statistics

Key Metrics

CVSS Score
LOW
Patches
1
Available
Remediation Protocol

Recommended Solution

No automatic solution found. Check vendor references.
Recommended Actions for Administrators

Immediate Action Plan

1. Inventory

Identify all affected systems in your infrastructure.

2. Assessment

Assess exposure and criticality for your organization.

3. Mitigation

Apply patches or available workarounds.

4. Verification

Test and confirm effectiveness of applied measures.