nodejs: permission model improperly protects against path traversal
Published Oct 18, 2023
7.5
HIGHCVSS 3.1
EPSS 1.32%
Description
A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined implementations.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.*
- Version 11.0StatusaffectedConstraints<11.*
- Version 12.0StatusaffectedConstraints<12.*
- Version 13.0StatusaffectedConstraints<13.*
- Version 14.0StatusaffectedConstraints<14.*
- Version 15.0StatusaffectedConstraints<15.*
- Version 16.0StatusaffectedConstraints<16.*
- Version 17.0StatusaffectedConstraints<17.*
- Version 19.0StatusaffectedConstraints<19.*
- Version 20.0StatusaffectedConstraints<20.8.1
- Version 4.0StatusaffectedConstraints<4.*
- Version 5.0StatusaffectedConstraints<5.*
- Version 6.0StatusaffectedConstraints<6.*
- Version 7.0StatusaffectedConstraints<7.*
- Version 8.0StatusaffectedConstraints<8.*
- Version 9.0StatusaffectedConstraints<9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Node.js | Node | unaffected |
|
No data.
Red Hat Enterprise Linux 8
nodejs:20-8090020231019152822.a75119d5
Fixed · RHSA-2023:7205
Red Hat Enterprise Linux 8
nodejs:16/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:18/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:18/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:20/nodejs
Not affected
Red Hat Software Collections
rh-nodejs14-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:20-8090020231019152822.a75119d5 | Fixed | RHSA-2023:7205 |
| Red Hat Enterprise Linux 8 | nodejs:16/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:20/nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 13, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.32% (0.01325) | 69.90th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.32% (0.01325) | 67.13th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.17% (0.01172) | 77.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00065) | 30.56th | v3 (v2023.03.01) |
| May 20, 2024 | 0.05% (0.00054) | 21.55th | v3 (v2023.03.01) |
| Nov 4, 2023 | 0.05% (0.00053) | 19.54th | v3 (v2023.03.01) |
| Oct 26, 2023 | 0.06% (0.00060) | 23.64th | v3 (v2023.03.01) |
| Oct 18, 2023 | 0.04% (0.00043) | 7.25th | v3 (v2023.03.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2023-39331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2244413 Issue Tracking
- https://hackerone.com/reports/2092852 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39331
- https://security.netapp.com/advisory/ntap-20231116-0009/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241108-0002/
- https://www.cve.org/CVERecord?id=CVE-2023-39331
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-39331 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2244413 | Issue Tracking | |
| https://hackerone.com/reports/2092852 | Third Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-39331 | ||
| https://security.netapp.com/advisory/ntap-20231116-0009/ | Third Party Advisory | |
| https://security.netapp.com/advisory/ntap-20241108-0002/ | ||
| https://www.cve.org/CVERecord?id=CVE-2023-39331 |
Change history (0)
No recorded changes yet.