CVE-2023-32005 is a medium-severity vulnerability in Node.js version 20, specifically impacting users of the experimental permission model when the --allow-fs-read flag is used with a non-wildcard argument. The flaw allows attackers to retrieve file statistics via the fs.statfs API even without explicit read access, due to an inadequate permission model. This vulnerability has a CVSS score of 5.3, indicating a low impact on confidentiality with no integrity or availability impact. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.0.0, < 20.5.1CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | ||
>= 20.0, < 20.5.1CPE match | cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.