BIT-node-2024-37372 PUBLISHED CVSS 3.5999999046325684 LOW

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

Risk Scores

CVSS v3.0
3.5999999046325684
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Bitnaminode19.0.0, 21.0.0, 19.0.0

Timeline

References

Open in Interactive Console →