Information disclosure in NPM - CVE-2022-29244

 

Information disclosure in NPM - CVE-2022-29244

Published: August 22, 2022


Vulnerability identifier: #VU66698
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29244
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, may be affected and have published files into the npm registry they did not intend to include.


Affected software

NPM
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Integration Bus
Spectrum Discover
IBM Spectrum Protect Plus
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Oracle Linux
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon (Red Hat package)
nodejs (Red Hat package)
nodejs16
nodejs16-debuginfo
nodejs16-debugsource
nodejs16-devel
npm16
nodejs16-docs
corepack16
IBM App Connect Enterprise
IBM QRadar Use Case Manager
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Space Management
IBM InfoSphere Information Server
Node.js

How to mitigate CVE-2022-29244

Install updates from vendor's website.

NPM - update to 8.11.0
Cloud Pak for Security (CP4S) - addressed in versions 1.10.7.0, 1.10.12.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.3
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.5.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el9_0
IBM QRadar Data Synchronization App - update to 3.1.1
IBM QRadar Use Case Manager - update to 3.6.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Spectrum Protect Plus - update to 10.1.14
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Node.js - addressed in versions 16.15.1, 17.9.1
nodejs (Red Hat package) - update to 16.16.0-1.el9_0
nodejs16 - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-debuginfo - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-debugsource - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-devel - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
npm16 - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-docs - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
corepack16 - update to 16.17.0-150400.3.6.1

External References

Related Security Bulletins