Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3jv-wrf4-5845

Опубликовано: 01 сент. 2020
Источник: github
Github: Прошло ревью

Описание

Local Privilege Escalation in npm

Affected versions of npm use predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns the npm process has permission to write to, potentially resulting in local privilege escalation.

Recommendation

Update to version 1.3.3 or later.

Пакеты

Наименование

npm

npm
Затронутые версииВерсия исправления

< 1.3.3

1.3.3

EPSS

Процентиль: 29%
0.00104
Низкий

Дефекты

CWE-59

Связанные уязвимости

ubuntu
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

redhat
больше 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

nvd
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

debian
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local us ...

EPSS

Процентиль: 29%
0.00104
Низкий

Дефекты

CWE-59