CVE-2023-30583
EUVD-2023-3496407.09.2024, 16:15
fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from a missing check in the `fs.openAsBlob()` API. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nodejs | nodejs | 20.0 ≤ 𝑥 < 20.3.1 | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration