A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the –allow-fs-write flag is used.
Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a read-only file descriptor to change the owner and permissions of a file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 8 | RedHat | nodejs:20-8100020240808073736.489197e6 | * |
Red Hat Enterprise Linux 9 | RedHat | nodejs:20-9040020240807145403.rhel9 | * |
Nodejs | Ubuntu | mantic | * |
Nodejs | Ubuntu | upstream | * |