npm CLI Çå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-16Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2019-16776£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
npm CLI <= 6.13.3
Îó²î¸ÅÊö
npm CLIÊÇÒ»¿îÈí¼þ°ü¹ÜÀíÆ÷¡£¡£¡£¡£¡£¡£¡£
Npm ¿ª·¢Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬npm ÏÂÁîÐнçÃæ£¨CLI£©¿Í»§¶ËÊܵ½ÁËÇå¾²Îó²îµÄÓ°Ï죬£¬£¬£¬£¬Í¬Ê±°üÀ¨Îļþ±éÀúºÍí§ÒâÎļþ£¨ÁýÕÖ£©Ð´ÈëÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøùýʧÀ´Ö²Èë¶ñÒâ¶þ½øÖÆÎļþ»òÁýÕÖÓû§ÅÌËã»úÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46
²Î¿¼Á´½Ó
https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/