Insufficient verification of data authenticity in CLI - CVE-2021-43616
Published: May 31, 2022 / Updated: June 1, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient verification of data authenticity in the npm ci command. A remote attacker can exploit the vulnerability to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json.
Affected software
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Cloud Pak for Security (CP4S)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2021-43616
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Cloud Pak for Watson AIOps - update to 3.5
nodejs - addressed in versions 16_epel-820220204180904.9edba152, 16.13.2-8.el7, 16.13.2-8.fc35, 16.14.0-2.el7, 16.14.0-2.fc35
nodejs - update to 18.12.1-1
External References
- https://docs.npmjs.com/cli/v7/commands/npm-ci
- https://github.com/npm/cli/issues/2701
- https://github.com/icatalina/CVE-2021-43616
- https://medium.com/cider-sec/this-time-we-were-lucky-85c0dcac94a0
- https://security.netapp.com/advisory/ntap-20211210-0002/
- https://github.com/npm/cli/commit/457e0ae61bbc55846f5af44afa4066921923490f
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NXNVFKOF5ZYH5NIRWHKN6O6UBCHDV6FE/
Related Security Bulletins
- Insufficient verification of data authenticity in npm cli
- Red Hat Enterprise Linux 8.6 update for the nodejs:16 module
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOPs
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Amazon Linux AMI update for nodejs
- Fedora 35 update for nodejs
- Fedora EPEL 7 update for nodejs
- Fedora Epel 8 Modular update for nodejs
- Fedora EPEL 7 update for nodejs
- Fedora 35 update for nodejs