Input validation error in Node.js - CVE-2024-37372

 

Input validation error in Node.js - CVE-2024-37372

Published: July 9, 2024


Vulnerability identifier: #VU93883
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37372
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass permissions model.

The vulnerability exists due to insufficient validation of UNC paths with backslashes. A remote user can bypass certain security restrictions.


Affected software

Node.js
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
Web and Scripting Module
openSUSE Leap
IBM Business Automation Workflow
EasyApache
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Planning Analytics Local
IBM Cognos Controller
nodejs20
nodejs20-debuginfo
npm20
nodejs20-devel
nodejs20-debugsource
nodejs20-docs
corepack20
net-libs/nodejs

How to mitigate CVE-2024-37372

Install updates from vendor's website.

Node.js - addressed in versions 20.15.1, 22.4.1
EasyApache - update to 4 2024-7-10
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
nodejs20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debuginfo - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
npm20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-devel - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debugsource - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-docs - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
corepack20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
net-libs/nodejs - update to 22.4.1

External References

Related Security Bulletins