CVE-2023-30583 describes a high-severity vulnerability in Node.js 20 where the fs.openAsBlob() function can bypass the experimental file system read restriction, even when the --allow-fs-read flag is used. This flaw stems from a missing security check, allowing unauthorized access to files. With a CVSS score of 7.5, this vulnerability presents a network-based attack vector with low complexity, potentially leading to high confidentiality impact without requiring user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.0, < 20.3.1CPE match | cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.