• CVE-2023-32558

发布时间: 2024年2月26日

修改时间: 2024年2月26日

概要

The use of the deprecated API process.binding() can bypass the permission model through path traversal. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. This vulnerability affects all users using the experimental permission model in Node.js 20.Security Advisory:https://nodejs.org/en/blog/vulnerability/august-2023-security-releases#processbinding-can-bypass-the-permission-model-through-path-traversal-highcve-2023-32558

CVSS v3 指标

NVD openEuler
CVSS评分 7.5 7.5
Attack Vector Network Network
Attack Complexity Low High
Privileges Required None Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality None High
Integrity High High
Availability None High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-1104 The use of the deprecated API process.binding() can bypass the permission model through path traversal. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. This vulnerability affects all users using the experimental permission model in Node.js 20.Security Advisory:https://nodejs.org/en/blog/vulnerability/august-2023-security-releases#processbinding-can-bypass-the-permission-model-through-path-traversal-highcve-2023-32558 2024年2月26日

影响产品

产品 状态
KY3.4-4A nodejs Unaffected
KY3.4-5A nodejs Unaffected
KY3.5.1 nodejs Unaffected
KY3.5.2 nodejs Unaffected