CVE-2024-36137

Source
https://cve.org/CVERecord?id=CVE-2024-36137
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36137.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-36137
Aliases
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CGA (2)
CLEANSTART (2)
DEBIAN (1)
MGASA (1)
OESA (2)
openSUSE (4)
RHSA (2)
RLSA (2)
SUSE (2)
UBUNTU (1)
Related
Published
2024-09-07T16:15:02Z
Modified
2026-06-24T09:14:56Z
Summary
[none]
Details

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.

Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

References

Affected packages