Input validation error in Node.js - CVE-2024-37372

 

Input validation error in Node.js - CVE-2024-37372

Published: July 9, 2024


Vulnerability identifier: #VU93883
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-37372
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Node.js
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
Web and Scripting Module
openSUSE Leap
IBM Business Automation Workflow
EasyApache
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Planning Analytics Local
IBM Cognos Controller
nodejs20
nodejs20-debuginfo
npm20
nodejs20-devel
nodejs20-debugsource
nodejs20-docs
corepack20
net-libs/nodejs

Detailed vulnerability description

The vulnerability allows a remote user to bypass permissions model.

The vulnerability exists due to insufficient validation of UNC paths with backslashes. A remote user can bypass certain security restrictions.


How to mitigate CVE-2024-37372

Install updates from vendor's website.

Sources