Incorrect default permissions in Node.js - CVE-2021-22921

 

Incorrect default permissions in Node.js - CVE-2021-22921

Published: July 8, 2021


Vulnerability identifier: #VU54625
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22921
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists in Windows installer due to incorrect default permissions for files and folders that are set by the application. A local user with access to the system can view contents of files and directories or modify them.


Affected software

Node.js
IBM Netcool Agile Service Manager
IBM Cloud Transformation Advisor
Rational Application Developer
IBM Spectrum Control
IBM Business Process Manager
IBM Business Automation Workflow
Planning Analytics Local
IBM Cognos Controller
IBM App Connect Enterprise
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Asset Repository in IBM Cloud Pak for Integration (CP4I)
SINEC INS

How to mitigate CVE-2021-22921

Install updates from vendor's website.

Node.js - addressed in versions 12.22.2, 14.17.2, 16.4.1
IBM Netcool Agile Service Manager - update to 1.1.13
Planning Analytics Local - update to 2.0.1
IBM Cloud Transformation Advisor - update to 2.5.0
IBM Cognos Controller - update to 11.0.1.0.3
IBM App Connect Enterprise - addressed in versions 11.0.0.14, 12.0.2.0
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-4, 2021.3.1
Asset Repository in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-3, 2021.2.1-1
SINEC INS - update to 1.0.1.1
IBM Spectrum Control - update to 5.4.4
IBM Business Process Manager - update to 8.5.7.0
IBM Business Automation Workflow - update to 21.0.3

External References

Related Security Bulletins