First published: Thu Dec 21 2023(Updated: )
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass when verifying file permissions. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics Cloud | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30584 has been classified with a moderate severity due to its potential impact on file permission verification.
To address CVE-2023-30584, it is recommended to upgrade to a later version of Node.js that resolves the experimental permission model flaw.
CVE-2023-30584 specifically affects Node.js version 20 and could impact applications dependent on this version.
CVE-2023-30584 is a path traversal vulnerability that occurs due to improper handling of file permissions.
At the time of this CVE, the permission model in Node.js is experimental, which contributes to the vulnerability concerns.