Bug 2230958 (CVE-2023-32005) - CVE-2023-32005 nodejs: fs.statfs can retrive stats from files restricted by the Permission Model
Summary: CVE-2023-32005 nodejs: fs.statfs can retrive stats from files restricted by t...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2023-32005
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2233395
Blocks: 2230962
TreeView+ depends on / blocked
 
Reported: 2023-08-10 10:08 UTC by Mauro Matteo Cascella
Modified: 2023-08-22 14:15 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-08-10 15:02:52 UTC
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2023-08-10 10:08:04 UTC
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.statfs API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. This vulnerability affects all users using the experimental permission model in Node.js 20.

Security Advisory:
https://nodejs.org/en/blog/vulnerability/august-2023-security-releases#fsstatfs-can-retrive-stats-from-files-restricted-by-the-permission-model-lowcve-2023-32005

Comment 1 Product Security DevOps Team 2023-08-10 15:02:51 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2023-32005

Comment 2 Sandipan Roy 2023-08-22 07:14:54 UTC
Created nodejs20 tracking bugs for this issue:

Affects: fedora-38 [bug 2233395]


Note You need to log in before you can comment on or make changes to this bug.