QID 980688
QID 980688: Nodejs (npm) Security Update for npm (GHSA-v3jv-wrf4-5845)
Affected versions of `npm` use predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns the `npm` process has permission to write to, potentially resulting in local privilege escalation.
## Recommendation
Update to version 1.3.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v3jv-wrf4-5845 for updates pertaining to this vulnerability.
Vendor References
- GHSA-v3jv-wrf4-5845 -
github.com/advisories/GHSA-v3jv-wrf4-5845
CVEs related to QID 980688
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v3jv-wrf4-5845 | npm |
|