PT-2018-3978 · Npm · Npm

Crunkle

·

Publicado

2018-02-22

·

Atualizado

2022-05-13

·

CVE-2018-7408

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions npm versions 5.7.0
Description The issue is related to the correctMkdir component of the npm package manager, which incorrectly assigns permissions for a critical resource. This could allow an attacker to bypass existing security restrictions. The problem might enable local users to bypass intended filesystem access restrictions because the ownerships of /etc and /usr directories are being changed unexpectedly.
Recommendations For npm version 5.7.0, consider restricting access to critical resources until a patch is available. As a temporary workaround, avoid using the correctMkdir component to minimize the risk of exploitation.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01409
CVE-2018-7408
GHSA-PH34-PC88-72GC

Produtos afetados

Npm