Incorrect default permissions in log4js-node - CVE-2022-21704
Published: March 24, 2022
Vulnerability identifier: #VU61582
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21704
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for log files created by the file, fileSync and dateFile appenders. A local user with access to the system can view contents of files and gain access to sensitive information.
Affected software
log4js-node
Cloudera Data Platform Private Cloud Base for IBM
IBM Cloud Pak for Watson AIOps
Cloudera Data Platform Private Cloud Base for IBM
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2022-21704
Install updates from vendor's website.
log4js-node - update to 6.4.0
IBM Cloud Pak for Watson AIOps - update to 3.6.2
IBM Cloud Pak for Watson AIOps - update to 3.6.2
External References
- https://github.com/log4js-node/log4js-node/blob/v6.4.0/CHANGELOG.md#640
- https://github.com/log4js-node/log4js-node/pull/1141/commits/8042252861a1b65adb66931fdf702ead34fa9b76
- https://github.com/log4js-node/streamroller/pull/87
- https://github.com/log4js-node/log4js-node/security/advisories/GHSA-82v2-mx6x-wq7q