Input validation error in Node.js - CVE-2024-37372
Published: July 9, 2024
Vulnerability identifier: #VU93883
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37372
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass permissions model.
The vulnerability exists due to insufficient validation of UNC paths with backslashes. A remote user can bypass certain security restrictions.
Affected software
Node.js
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
Web and Scripting Module
openSUSE Leap
IBM Business Automation Workflow
EasyApache
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Planning Analytics Local
IBM Cognos Controller
nodejs20
nodejs20-debuginfo
npm20
nodejs20-devel
nodejs20-debugsource
nodejs20-docs
corepack20
net-libs/nodejs
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
Web and Scripting Module
openSUSE Leap
IBM Business Automation Workflow
EasyApache
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Planning Analytics Local
IBM Cognos Controller
nodejs20
nodejs20-debuginfo
npm20
nodejs20-devel
nodejs20-debugsource
nodejs20-docs
corepack20
net-libs/nodejs
How to mitigate CVE-2024-37372
Install updates from vendor's website.
Node.js - addressed in versions 20.15.1, 22.4.1
EasyApache - update to 4 2024-7-10
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
nodejs20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debuginfo - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
npm20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-devel - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debugsource - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-docs - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
corepack20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
net-libs/nodejs - update to 22.4.1
EasyApache - update to 4 2024-7-10
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
nodejs20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debuginfo - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
npm20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-devel - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debugsource - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-docs - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
corepack20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
net-libs/nodejs - update to 22.4.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- SUSE update for nodejs20
- SUSE update for nodejs20
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Gentoo update for Node.js