CVE-2019-16777

Aliases:GHSA-4328-8hgf-7wjrDEBIAN-CVE-2019-16777CGA-2743-gvgv-v398CGA-238g-gvc7-v63rCGA-28fj-8g34-rrj9CGA-2c5q-rcv3-rw8wCGA-2ccj-q843-9gc8CGA-2cmh-cjmv-3cx3CGA-2jmq-4r46-9fjfCGA-2rvv-74c4-69ggCGA-33pf-754j-hhpgCGA-355h-7c7h-rwwhCGA-363f-g38g-gmmxCGA-377c-xrj4-4cp6CGA-39gx-vcqf-m63pCGA-39w5-v9g5-j2rcCGA-3j8p-hghw-q2r9CGA-3jvj-2v8h-rj97CGA-3mhj-h32m-f89qCGA-3php-7qgp-xqg6CGA-43mr-82rf-2q3mCGA-4h27-5c79-c7mqCGA-4wjc-hg2x-frwmCGA-5388-4hr8-g6hgCGA-53vx-mrwq-4v6hCGA-5j7q-hr9q-8w7xCGA-65rw-8378-8pwwCGA-68m3-pw3f-gjm3CGA-6fhh-87w9-6g9rCGA-6g7q-7v76-h927CGA-6j2g-jwvx-jwqmCGA-6x6f-fwp9-5v6qCGA-74v9-864x-4964CGA-7984-9vcj-rchqCGA-7g24-x424-w93hCGA-7mq3-pphm-2px8CGA-88pw-g94p-r57rCGA-892m-hvhm-qwhmCGA-8988-737m-c47fCGA-8r8w-pc77-4wp5CGA-92fj-v34j-r3j2CGA-94wc-wrc4-ppxcCGA-99qh-hj8w-crf8CGA-99x3-q595-2xccCGA-9cc5-298h-gx3rCGA-c8f9-j25v-7c8xCGA-c9pw-pw8f-cvx5CGA-chv7-j4cc-mmfhCGA-cvq7-rcc5-xxq2CGA-f2g7-h65r-3475CGA-f36q-78mc-298cCGA-fh2w-4pp2-358hCGA-fhmj-xp6w-8792CGA-fqr9-9qqp-vvhgCGA-g685-cg3h-m62pCGA-g98w-p3q4-c7qvCGA-gc9h-qhp5-pqvwCGA-ggmf-pf5m-c5v7CGA-ghr8-r3x3-ffrhCGA-gjq8-w63v-hj33CGA-gq3j-56jj-qvh9CGA-gx66-vxq3-4q6hCGA-h38f-9v8p-j79qCGA-h492-vg9v-67jgCGA-h763-m2cw-3mwmCGA-hc5j-j97j-g8gwCGA-hc5v-j3m2-p2hxCGA-hggf-rwgp-vfwqCGA-hm64-jg3c-2ghpCGA-hm6g-hcjj-vrw7CGA-j24r-gjxp-7vvfCGA-j2f6-rcvq-fhh6CGA-j2pv-5pwc-cq32CGA-j78w-284x-6jrhCGA-j85w-crx6-5c4jCGA-j88c-rpwp-c76cCGA-jh2g-wqxj-wgwvCGA-jw57-wwcx-whcjCGA-jwv6-87mm-h6fcCGA-jxf7-fmv4-fhggCGA-jxfw-qxmv-8gx8CGA-m2cv-vf4m-37hcCGA-m35h-jff8-ggmwCGA-m5vr-h29p-c4vpCGA-m7c3-5g26-p473CGA-mc5x-xp3v-7h8xCGA-mcr4-q42x-p434CGA-mhqm-jfc6-23w8CGA-mj32-3p8c-4q33CGA-mjc4-vfxj-89vhCGA-mp4p-j3wm-3mjjCGA-mvp6-4qwg-fh36CGA-mxjh-5xc9-39jpCGA-pc24-4q29-65f7CGA-pvq6-6x96-x8xjCGA-pwqq-jx55-cwwwCGA-q2j4-jq74-3cghCGA-q3h8-5vpg-8rxfCGA-q3xv-mfx7-cv89CGA-q8hp-9m22-hjcxCGA-qg4v-5g7w-32gvCGA-qr53-hfjx-j43xCGA-r3cf-9m5r-3gp3CGA-r538-68g2-hqq4CGA-r5hm-3gxh-whwjCGA-rc2v-6j7j-686qCGA-rp83-jc9p-j6vrCGA-rpcp-fhhh-rqvwCGA-v2q7-vg7v-fc5gCGA-v2rh-g83g-9vx4CGA-v3hc-wpq3-pv38CGA-v3q2-vjxv-4jwxCGA-v75w-3wxw-jfrwCGA-v8x4-w2mg-8422CGA-v9v6-2fmg-5hp9CGA-vcg3-ghf3-w6q2CGA-vh39-hx6r-847rCGA-vjf3-cpvw-562rCGA-vvx7-88f5-fccmCGA-vwp3-7wrr-jwwgCGA-vx89-69wf-38v4CGA-vxpj-gwpx-5hrgCGA-w375-hrxj-3qfcCGA-w4pw-vmmx-gjffCGA-w4vw-2hqp-x787CGA-wh2p-6gh2-38wfCGA-wxv3-x2cq-gqjcCGA-xgmg-6h78-2fxwCGA-xh67-8wpx-8x7gCGA-xjgv-27xr-r79rCGA-xr84-jrcp-p472CGA-xw4v-3chx-86hgCGA-xwg3-v7rc-vfc8CGA-xxp2-j478-f55cCGA-4mcf-m53p-mj98CGA-4xj2-584w-29j5CGA-5j27-qggm-ff92CGA-pv48-m4gh-pqwwCGA-4rqr-rc57-cx78CGA-5frw-w2rx-m34cCGA-pr3g-qcp3-5556CGA-hrv5-fcx2-r2qqCGA-mh73-jcgg-jfgcCGA-v8fh-j8gx-hm33CGA-xv4h-9x5j-mrfvCGA-4mcq-7v5x-pqpvCGA-4qh9-p6hv-86pjCGA-5c5q-xx5h-6rr6CGA-w9fq-439v-r6xr
Modified
Published: 13 Dec 2019, 01:00
Last modified:05 Aug 2024, 01:24

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.7 HIGH
v3.1 (cve.org)
EPSS Score
2.04% LOW
2% probability +1.69%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Dec 2019, 01:00
Published
Vulnerability first disclosed
05 Aug 2024, 01:24
Last Modified
Vulnerability information updated

Description

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVSS Metrics

  • v3.1HIGHScore: 7.7CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 5.5AV:N/AC:L/Au:S/C:N/I:P/A:P

EPSS Trends

Current EPSS score: 2.04% Percentile: 80%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

  • CWE-269Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Systems

  • chainguardcode-server

    < 0

  • chainguardcode-server-compat

    < 0

  • chainguardcommercial-gitlab-rails-ee-assets-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-assets-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-assets-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-assets-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-assets-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-assets-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.1

    < 0

  • chainguardgitlab-rails-ce-18.2

    < 0

  • chainguardgitlab-rails-ce-18.3

    < 0

  • chainguardgitlab-rails-ce-18.4

    < 0

  • chainguardgitlab-rails-ce-18.5

    < 0

  • chainguardgitlab-rails-ce-18.6

    < 0

  • chainguardgitlab-rails-ce-18.7

    < 0

  • chainguardgitlab-rails-ce-assets-18.1

    < 0

  • chainguardgitlab-rails-ce-assets-18.10

    < 0

  • chainguardgitlab-rails-ce-assets-18.11

    < 0

  • chainguardgitlab-rails-ce-assets-18.2

    < 0

  • chainguardgitlab-rails-ce-assets-18.3

    < 0

  • chainguardgitlab-rails-ce-assets-18.4

    < 0

  • chainguardgitlab-rails-ce-assets-18.5

    < 0

  • chainguardgitlab-rails-ce-assets-18.6

    < 0

  • chainguardgitlab-rails-ce-assets-18.7

    < 0

  • chainguardgitlab-rails-ce-assets-18.8

    < 0

  • chainguardgitlab-rails-ce-assets-18.9

    < 0

  • chainguardgitlab-rails-ce-assets-19.0

    < 0

  • chainguardgitlab-rails-ce-assets-19.1

    < 0

  • chainguardgitlab-rails-ce-assets-19.2

    < 0

  • chainguardgitlab-rails-ce-assets-19.3

    < 0

  • chainguardgitlab-rails-ce-assets-19.4

    all

  • chainguardgitlab-rails-ce-assets-fips-18.1

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.10

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.11

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.2

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.3

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.4

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.5

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.6

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.7

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.8

    < 0

  • chainguardgitlab-rails-ce-assets-fips-18.9

    < 0

  • chainguardgitlab-rails-ce-assets-fips-19.0

    < 0

  • chainguardgitlab-rails-ce-assets-fips-19.1

    < 0

  • chainguardgitlab-rails-ce-assets-fips-19.2

    < 0

  • chainguardgitlab-rails-ce-assets-fips-19.3

    < 0

  • chainguardgitlab-rails-ce-assets-fips-19.4

    all

  • chainguardgitlab-rails-ce-doc-18.1

    < 0

  • chainguardgitlab-rails-ce-doc-18.2

    < 0

  • chainguardgitlab-rails-ce-doc-18.3

    < 0

Showing first 50 affected entries in server-rendered view.

References (17)