ALT-PU-2020-2196-1
Closed vulnerabilities
BDU:2019-04689
Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю перезаписать произвольные файлы в контексте целевого каталога
BDU:2019-04690
Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю записывать произвольные файлы
BDU:2019-04691
Уязвимость набора инструментов командной строки пакетных менеджеров NPM и Yarn, позволяющая нарушителю записывать произвольные файлы
Modified: 2024-11-21
CVE-2019-16775
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
- openSUSE-SU-2020:0059
- openSUSE-SU-2020:0059
- RHEA-2020:0330
- RHEA-2020:0330
- RHSA-2020:0573
- RHSA-2020:0573
- RHSA-2020:0579
- RHSA-2020:0579
- RHSA-2020:0597
- RHSA-2020:0597
- RHSA-2020:0602
- RHSA-2020:0602
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
- https://github.com/npm/cli/security/advisories/GHSA-m6cx-g6qm-p2cx
- https://github.com/npm/cli/security/advisories/GHSA-m6cx-g6qm-p2cx
- FEDORA-2020-595ce5e3cc
- FEDORA-2020-595ce5e3cc
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Modified: 2024-11-21
CVE-2019-16776
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
- openSUSE-SU-2020:0059
- openSUSE-SU-2020:0059
- RHEA-2020:0330
- RHEA-2020:0330
- RHSA-2020:0573
- RHSA-2020:0573
- RHSA-2020:0579
- RHSA-2020:0579
- RHSA-2020:0597
- RHSA-2020:0597
- RHSA-2020:0602
- RHSA-2020:0602
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
- https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46
- https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46
- FEDORA-2020-595ce5e3cc
- FEDORA-2020-595ce5e3cc
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
Modified: 2024-11-21
CVE-2019-16777
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
- openSUSE-SU-2020:0059
- openSUSE-SU-2020:0059
- RHEA-2020:0330
- RHEA-2020:0330
- RHSA-2020:0573
- RHSA-2020:0573
- RHSA-2020:0579
- RHSA-2020:0579
- RHSA-2020:0597
- RHSA-2020:0597
- RHSA-2020:0602
- RHSA-2020:0602
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
- https://github.com/npm/cli/security/advisories/GHSA-4328-8hgf-7wjr
- https://github.com/npm/cli/security/advisories/GHSA-4328-8hgf-7wjr
- FEDORA-2020-595ce5e3cc
- FEDORA-2020-595ce5e3cc
- GLSA-202003-48
- GLSA-202003-48
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html