Логотип exploitDog
bind:"BDU:2019-04691" OR bind:"CVE-2019-16775"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2019-04691" OR bind:"CVE-2019-16775"

Количество 14

Количество 14

fstec логотип

BDU:2019-04691

больше 5 лет назад

Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю записывать произвольные файлы

CVSS3: 7.7
EPSS: Низкий
ubuntu логотип

CVE-2019-16775

больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
EPSS: Низкий
redhat логотип

CVE-2019-16775

больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2019-16775

больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2019-16775

больше 5 лет назад

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary ...

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-m6cx-g6qm-p2cx

больше 5 лет назад

Arbitrary File Write in npm

CVSS3: 7.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0059-1

больше 5 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0247-1

больше 5 лет назад

Security update for nodejs6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0104-1

больше 5 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0063-1

больше 5 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0043-1

больше 5 лет назад

Security update for nodejs8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0429-1

больше 5 лет назад

Security update for nodejs12

EPSS: Низкий
rocky логотип

RLSA-2020:0579

больше 5 лет назад

Important: nodejs:10 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0579

больше 5 лет назад

ELSA-2020-0579: nodejs:10 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-04691

Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю записывать произвольные файлы

CVSS3: 7.7
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 4.8
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS3: 7.7
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary ...

CVSS3: 7.7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-m6cx-g6qm-p2cx

Arbitrary File Write in npm

CVSS3: 7.7
0%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0059-1

Security update for nodejs8

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0247-1

Security update for nodejs6

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0104-1

Security update for nodejs10

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0063-1

Security update for nodejs10

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0043-1

Security update for nodejs8

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0429-1

Security update for nodejs12

больше 5 лет назад
rocky логотип
RLSA-2020:0579

Important: nodejs:10 security update

больше 5 лет назад
oracle-oval логотип
ELSA-2020-0579

ELSA-2020-0579: nodejs:10 security update (IMPORTANT)

больше 5 лет назад

Уязвимостей на страницу