VDB

CVE-2024-37372

CVE-2024-37372 PUBLISHED CVSS 3.5999999046325684 LOW

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

EPSS 0.49% · 39.6th percentile

Risk Scores

CVSS 3.0
3.5999999046325684
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.49%
39.6th percentile

Affected Products

VendorProductVersions
Bitnaminode21.0.0, 21.0.0, 19.0.0
Bitnaminode21.0.0, 19.0.0
Bitnaminode-min21.0.0, 19.0.0
Bitnaminode-min21.0.0, 19.0.0, 19.0.0

Timeline

  • CVE Published
  • Jul 15, 2024 PoC Published
  • Jan 9, 2025 EPSS Score
  • Jan 25, 2025 EPSS Score
  • Feb 10, 2025 EPSS Score
  • Feb 27, 2025 EPSS Score
  • Mar 5, 2025 Coalition ESS Score
  • Mar 15, 2025 EPSS Score
  • Mar 31, 2025 EPSS Score
  • Apr 16, 2025 EPSS Score
  • May 2, 2025 EPSS Score
  • May 18, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›