UNIX symbolic link following in arborist - CVE-2021-39135

 

UNIX symbolic link following in arborist - CVE-2021-39135

Published: March 11, 2022


Vulnerability identifier: #VU61257
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39135
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists due to a symlink following issue. A local attacker can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

arborist
IBM Engineering Requirements Quality Assistant
Gentoo Linux
SUSE Linux Enterprise Module for Web Scripting
IBM Security Verify Governance
SINEC INS
nodejs12
nodejs12-debuginfo
nodejs12-debugsource
nodejs12-devel
npm12
nodejs12-docs
nodejs14-docs
npm14
nodejs14-devel
nodejs14-debugsource
nodejs14-debuginfo
nodejs14

How to mitigate CVE-2021-39135

Install updates from vendor's website.

arborist - update to 2.8.2
SINEC INS - update to 1.0.1.1
nodejs12 - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-debuginfo - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-debugsource - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-devel - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
npm12 - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs12-docs - addressed in versions 12.22.7-4.22.1, 12.22.9-1.38.1
nodejs14-docs - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
npm14 - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14-devel - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14-debugsource - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14-debuginfo - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2
nodejs14 - addressed in versions 14.18.1-6.18.2, 14.18.1-15.21.2

External References

Related Security Bulletins