Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-16775

Опубликовано: 13 дек. 2019
Источник: debian

Описание

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
npmfixed6.13.4+ds-1experimentalpackage
npmfixed6.13.4+ds-2package
npmfixed5.8.0+ds6-4+deb10u1busterpackage
npmend-of-lifejessiepackage

Примечания

  • https://github.com/npm/cli/security/advisories/GHSA-m6cx-g6qm-p2cx

  • https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 4.8
redhat
больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
nvd
больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
github
больше 5 лет назад

Arbitrary File Write in npm

CVSS3: 7.7
fstec
больше 5 лет назад

Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю записывать произвольные файлы