Описание
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
A flaw was found in pnpm, a package manager. A remote attacker could exploit this vulnerability by providing a specially crafted patch entry. This crafted entry could resolve outside the configured patches directory, allowing for the deletion of an arbitrary file when pnpm patch-remove is executed. This could lead to data integrity issues or a denial of service.
Отчет
This is an Important flaw in pnpm where a crafted patch entry can enable arbitrary file deletion. When the pnpm patch-remove command processes such an entry, it may resolve paths outside the intended patches directory, allowing the deletion of arbitrary files. While the primary issue is addressed by validating paths, a local attacker could still exploit a time-of-check/time-of-use race condition to achieve similar effects.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | pnpm | Not affected | ||
| Red Hat Build of Keycloak | pnpm | Affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | pnpm | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | pnpm | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patc ...
EPSS
7.1 High
CVSS3