Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16777

Опубликовано: 12 дек. 2019
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Workspaces 1npmAffected
Red Hat OpenShift Application Runtimesnodejs8Out of support scope
Red Hat Enterprise Linux 8nodejsFixedRHEA-2020:033004.02.2020
Red Hat Enterprise Linux 8nodejsFixedRHSA-2020:057925.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsnodejsFixedRHSA-2020:057324.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs10-nodejsFixedRHSA-2020:059725.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2020:060225.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs8-nodejsFixedRHSA-2020:262519.06.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-nodejs10-nodejsFixedRHSA-2020:059725.02.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-nodejs12-nodejsFixedRHSA-2020:060225.02.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1788301npm: Global node_modules Binary Overwrite

EPSS

Процентиль: 52%
0.00287
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
nvd
больше 5 лет назад

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
debian
больше 5 лет назад

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary ...

CVSS3: 7.7
github
больше 5 лет назад

npm Vulnerable to Global node_modules Binary Overwrite

CVSS3: 7.7
fstec
больше 5 лет назад

Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю перезаписать произвольные файлы в контексте целевого каталога

EPSS

Процентиль: 52%
0.00287
Низкий

4.8 Medium

CVSS3