PT-2018-3978 · Npm · Npm

Crunkle

·

Published

2018-02-22

·

Updated

2022-05-13

·

CVE-2018-7408

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions npm versions 5.7.0
Description The issue is related to the correctMkdir component of the npm package manager, which incorrectly assigns permissions for a critical resource. This could allow an attacker to bypass existing security restrictions. The problem might enable local users to bypass intended filesystem access restrictions because the ownerships of /etc and /usr directories are being changed unexpectedly.
Recommendations For npm version 5.7.0, consider restricting access to critical resources until a patch is available. As a temporary workaround, avoid using the correctMkdir component to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01409
CVE-2018-7408
GHSA-PH34-PC88-72GC

Affected Products

Npm