← Retour aux CVEs
CVE-2019-16776
HIGH7.7
Description
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Details CVE
Score CVSS v3.17.7
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie12/13/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
fedoraproject:fedoranpmjs:npmopensuse:leaporacle:graalvmredhat:enterprise_linuxredhat:enterprise_linux_eus
Faiblesses (CWE)
CWE-22CWE-22
References
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00027.html(security-advisories@github.com)
https://access.redhat.com/errata/RHEA-2020:0330(security-advisories@github.com)
https://access.redhat.com/errata/RHSA-2020:0573(security-advisories@github.com)
https://access.redhat.com/errata/RHSA-2020:0579(security-advisories@github.com)
https://access.redhat.com/errata/RHSA-2020:0597(security-advisories@github.com)
https://access.redhat.com/errata/RHSA-2020:0602(security-advisories@github.com)
https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli(security-advisories@github.com)
https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46(security-advisories@github.com)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/(security-advisories@github.com)
https://www.oracle.com/security-alerts/cpujan2020.html(security-advisories@github.com)
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00027.html(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHEA-2020:0330(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2020:0573(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2020:0579(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2020:0597(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2020:0602(af854a3a-2127-422b-91ae-364da2661108)
https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2020.html(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.