Node.js
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*, +2 more
- >= 20.0.0, < 20.15.0
- >= 22.0.0, < 22.4.0
A vulnerability exists in the Node.js Permission Model on Windows, specifically in versions 20.0.0 prior to 20.15.0 and 22.0.0 prior to 22.4.0. The issue arises because the Permission Model incorrectly assumes that any path beginning with two backslashes has a four-character prefix that can be disregarded, which is not always the case. This flaw can lead to vulnerable edge cases.
Exploitation of this vulnerability could result in unauthorized access to files or data, allowing for potential disclosure of sensitive information or unauthorized modification of data.
Users can upgrade to Node.js versions 20.15.1 or 22.4.1 to address this vulnerability. NetApp products incorporating Node.js should also be updated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.