QID 376484
Date Published: 2022-03-22
QID 376484: Node-IPC NPM Package Arbitrary File Overwrite Vulnerability
The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address.The maintainer removed the malicious code in version 10.1.3.
Affected Versions:
Node-ipc versions 10.1.1 and 10.1.2
QID detection logic(Authenticated): This QID checks for vulnerable versions of Node-IPC package using the npm list -g command.
Note: Node-IPC is a npm package that can be installed as a global, developer and production dependency. We can only detect node-ipc package if it is installed globally(as a global dependency). This QID checks for vulnerable version of node-ipc at default location only.
Successful exploitation of the vulnerability may allow remote attackers to change file content.
- Node-IPC Security Advisory -
github.com/advisories/GHSA-97m3-w2cp-4xx6
CVEs related to QID 376484
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|