Information disclosure in NPM - CVE-2022-29244
Published: August 22, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to npm pack ignores root-level .gitignore and .npmignore file exclusion
directives when run in a workspace or with a workspace flag (ie.
`--workspaces`, `--workspace=
Affected software
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Integration Bus
Spectrum Discover
IBM Spectrum Protect Plus
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Oracle Linux
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon (Red Hat package)
nodejs (Red Hat package)
nodejs16
nodejs16-debuginfo
nodejs16-debugsource
nodejs16-devel
npm16
nodejs16-docs
corepack16
IBM App Connect Enterprise
IBM QRadar Use Case Manager
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Space Management
IBM InfoSphere Information Server
Node.js
How to mitigate CVE-2022-29244
Cloud Pak for Security (CP4S) - addressed in versions 1.10.7.0, 1.10.12.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.3
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.5.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el9_0
IBM QRadar Data Synchronization App - update to 3.1.1
IBM QRadar Use Case Manager - update to 3.6.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Spectrum Protect Plus - update to 10.1.14
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Node.js - addressed in versions 16.15.1, 17.9.1
nodejs (Red Hat package) - update to 16.16.0-1.el9_0
nodejs16 - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-debuginfo - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-debugsource - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-devel - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
npm16 - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
nodejs16-docs - addressed in versions 16.17.0-8.9.1, 16.17.0-150300.7.9.1, 16.17.0-150400.3.6.1
corepack16 - update to 16.17.0-150400.3.6.1
External References
- https://github.com/nodejs/node/pull/43210
- https://github.com/nodejs/node/releases/tag/v18.3.0
- https://github.com/npm/cli/security/advisories/GHSA-hj9c-8jmm-8c52
- https://github.com/npm/cli/tree/latest/workspaces/libnpmpack
- https://github.com/nodejs/node/releases/tag/v17.9.1
- https://github.com/npm/npm-packlist
- https://github.com/npm/cli/tree/latest/workspaces/libnpmpublish
- https://github.com/npm/cli/releases/tag/v8.11.0
- https://github.com/nodejs/node/releases/tag/v16.15.1
- https://security.netapp.com/advisory/ntap-20220722-0007/
Related Security Bulletins
- Unintended information disclosure in NPM
- Node.js update for NPM
- SUSE update for nodejs16
- SUSE update for nodejs16
- SUSE update for nodejs16
- Red Hat Enterprise Linux 9 update for nodejs and nodejs-nodemon
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Multiple vulnerabilities in IBM Spectrum Protect Client and IBM Spectrum Protect for Space Management
- Multiple vulnerabilities in IBM Use Case Manager
- Multiple vulnerabilities in IBM QRadar Data Synchronization
- Information disclosure in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Discover
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data