CVE Database
/

CVE-2019-16777

Back to search

CVE-2019-16777

Published: Dec 13, 2019

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.1

7.7

HIGH

Description

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

VendorProductVersions

npm

cli

affected
< 6.13.4 - < 6.13.4

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

None

References

openSUSE-SU-2020:0059
vendor-advisory
x_refsource_SUSE
FEDORA-2020-595ce5e3cc
vendor-advisory
x_refsource_FEDORA
RHEA-2020:0330
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0573
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0579
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0597
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0602
vendor-advisory
x_refsource_REDHAT
GLSA-202003-48
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now