Symlink following in NPM - CVE-2019-16775
Published: January 2, 2020 / Updated: February 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
Versions of the npm CLI prior to 6.13.3 are vulnerable to a symlink reference outside of node_modules. It is possible for packages to create symlinks to files outside of the node_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user’s system when the package is installed. Only files accessible by the user running the npm install are affected.
Affected software
Red Hat Software Collections
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for IBM z Systems
Opensuse
IBM VM Recovery Manager DR
IBM InfoSphere Information Server
How to mitigate CVE-2019-16775
IBM VM Recovery Manager DR - update to 1.5.0.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Multiple vulnerabilities in npm package for Node.js
- Red Hat update for nodejs:10 module
- Red Hat 8 update for nodejs:10
- Red Hat Software Collections security update for rh-nodejs12-nodejs
- Red Hat Software Collections update for rh-nodejs10-nodejs
- Red Hat Enterprise Linux 8 update for nodejs:12
- OpenSUSE Linux update for nodejs8
- Multiple vulnerabilities in IBM VM Recovery Manager DR
- Multiple vulnerabilities in IBM InfoSphere Information Server