npm CLI Çå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-16

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£º CVE-2019-16776£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


npm CLI <= 6.13.3


Îó²î¸ÅÊö


npm CLIÊÇÒ»¿îÈí¼þ°ü¹ÜÀíÆ÷ ¡£¡£¡£¡£¡£¡£¡£


Npm ¿ª·¢Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬npm ÏÂÁîÐнçÃæ£¨CLI£©¿Í»§¶ËÊܵ½ÁËÇå¾²Îó²îµÄÓ°Ï죬£¬£¬£¬£¬Í¬Ê±°üÀ¨Îļþ±éÀúºÍí§ÒâÎļþ£¨ÁýÕÖ£©Ð´ÈëÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøùýʧÀ´Ö²Èë¶ñÒâ¶þ½øÖÆÎļþ»òÁýÕÖÓû§ÅÌËã»úÉϵÄÎļþ ¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46


²Î¿¼Á´½Ó


https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/