PT-2018-3978 · Npm · Npm
Crunkle
·
Published
2018-02-22
·
Updated
2022-05-13
·
CVE-2018-7408
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
npm versions 5.7.0
Description
The issue is related to the
correctMkdir component of the npm package manager, which incorrectly assigns permissions for a critical resource. This could allow an attacker to bypass existing security restrictions. The problem might enable local users to bypass intended filesystem access restrictions because the ownerships of /etc and /usr directories are being changed unexpectedly.Recommendations
For npm version 5.7.0, consider restricting access to critical resources until a patch is available. As a temporary workaround, avoid using the
correctMkdir component to minimize the risk of exploitation.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Npm