CVE-2023-30584
Last modified
CVE-2023-30584 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass when verifying file permissions. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass when verifying file permissions. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-30584?
How severe is CVE-2023-30584?
How do I fix CVE-2023-30584?
Are you affected by CVE-2023-30584?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
