Описание
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.
A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to serve malicious software packages if the codeload.github.com server is compromised or a user's machine configuration is tampered with. The issue arises because pnpm does not verify the integrity of dependencies downloaded from https://codeload.github.com against its lockfile. This could lead to the installation of unverified and potentially malicious code, resulting in arbitrary code execution on the affected system.
Отчет
This Important vulnerability in pnpm, as shipped in Red Hat products, exposes users to supply chain attacks by failing to verify the integrity of dependencies sourced from codeload.github.com. If the codeload.github.com server is compromised or a user's local machine configuration is tampered with, pnpm could install malicious software packages without detection, leading to arbitrary code execution. This risk is heightened in environments where developers rely on GitHub git dependencies without additional integrity checks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | pnpm | Not affected | ||
| Red Hat Build of Keycloak | pnpm | Affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | pnpm | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | pnpm | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious co ...
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
7.5 High
CVSS3