CVE-2023-32558

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
12/09/2023
Last modified:
04/12/2023

Description

The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. <br /> <br /> This vulnerability affects all users using the experimental permission model in Node.js 20.x.<br /> <br /> Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 20.0.0 (including) 20.5.1 (excluding)


References to Advisories, Solutions, and Tools