DirectorySecurity Advisories
Sign In
Security Advisories

CGA-98vh-v44p-jcg7

Published

Last updated

https://images.chainguard.dev/security/CGA-98vh-v44p-jcg7
Package

gitlab-rails-ee-17.1

Latest Update
Not affected
Aliases
  • CVE-2019-16775
  • GHSA-m6cx-g6qm-p2cx

Severity

7.7

High

CVSS V3

Summary

Arbitrary File Write in npm

Description

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to create files on a user's system when the package is installed. It is only possible to affect files that the user running npm install has access to and it is not possible to over write files that already exist on disk.

This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

Recommendation

Upgrade to version 6.13.3 or later.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images