Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16776

Опубликовано: 12 дек. 2019
Источник: redhat
CVSS3: 4.8

Описание

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Workspaces 1npmAffected
Red Hat OpenShift Application Runtimesnodejs8Out of support scope
Red Hat Enterprise Linux 8nodejsFixedRHEA-2020:033004.02.2020
Red Hat Enterprise Linux 8nodejsFixedRHSA-2020:057925.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsnodejsFixedRHSA-2020:057324.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs10-nodejsFixedRHSA-2020:059725.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2020:060225.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs8-nodejsFixedRHSA-2020:262519.06.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-nodejs10-nodejsFixedRHSA-2020:059725.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-nodejs12-nodejsFixedRHSA-2020:060225.02.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1788310npm: Arbitrary file write via constructed entry in the package.json bin field

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
nvd
больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
debian
больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary ...

CVSS3: 7.7
github
больше 5 лет назад

npm symlink reference outside of node_modules

CVSS3: 7.7
fstec
больше 5 лет назад

Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю записывать произвольные файлы

4.8 Medium

CVSS3