Записи npmjs
18 опубликованных записей вендора npmjs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 88,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-61 UNIX Symbolic Link (Symlink) Following3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-1333 Inefficient Regular Expression Complexity2
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-345 Insufficient Verification of Data Authenticity1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-43616Proof of concept | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differnpmjs · npm · CWE-345 | Критическая9,8 | — | 2,7 % | 13 нояб. 2021 г. |
35Наблюдать | CVE-2021-37701Эксплойта нет | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linksnpmjs · tar · CWE-22 | Высокая8,6 | — | 3,3 % | 31 авг. 2021 г. |
35Наблюдать | CVE-2021-37712Эксплойта нет | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linksnpmjs · tar · CWE-22 | Высокая8,6 | — | 1,9 % | 31 авг. 2021 г. |
34Наблюдать | CVE-2021-37713Эксплойта нет | Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitizationnpmjs · tar · CWE-22 | Высокая8,6 | — | 1,3 % | 31 авг. 2021 г. |
33Наблюдать | CVE-2019-16776Эксплойта нет | Unauthorized File Access in npm CLI before before version 6.13.3npmjs · npm · CWE-22 | Высокая8,1 | — | 3,4 % | 12 дек. 2019 г. |
32Наблюдать | CVE-2016-3956Эксплойта нет | The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 beforeibm · sdk · CWE-200 | Высокая7,5 | — | 6,7 % | 2 июл. 2016 г. |
31Наблюдать | CVE-2022-29244Эксплойта нет | npm packing does not respect root-level ignore files in workspacesnpmjs · npm · CWE-200 | Высокая7,5 | — | 3,9 % | 13 июн. 2022 г. |
31Наблюдать | CVE-2020-7754Эксплойта нет | Regular Expression Denial of Service (ReDoS)npmjs · npm-user-validate | Высокая7,5 | — | 3,5 % | 27 окт. 2020 г. |
31Наблюдать | CVE-2022-25883Эксплойта нет | Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when npmjs · semver · CWE-1333 | Высокая7,5 | — | 2,8 % | 21 июн. 2023 г. |
31Наблюдать | CVE-2021-39134Эксплойта нет | UNIX Symbolic Link (Symlink) Following in @npmcli/arboristnpmjs · arborist · CWE-61 | Высокая7,8 | — | 0,6 % | 31 авг. 2021 г. |
31Наблюдать | CVE-2021-39135Эксплойта нет | UNIX Symbolic Link (Symlink) Following in @npmcli/arboristnpmjs · arborist · CWE-61 | Высокая7,8 | — | 0,6 % | 31 авг. 2021 г. |
31Наблюдать | CVE-2018-7408Эксплойта нет | An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgnpmjs · npm · CWE-732 | Высокая7,8 | — | 0,3 % | 22 февр. 2018 г. |
30Наблюдать | CVE-2024-21523Эксплойта нет | All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fuCWE-400 | Высокая7,5 | — | 0,6 % | 10 июл. 2024 г. |
30Наблюдать | CVE-2024-25354Эксплойта нет | RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function. | Высокая7,5 | — | 0,6 % | 27 мар. 2024 г. |
27Наблюдать | CVE-2019-16775Эксплойта нет | Unauthorized File Access in npm CLI before before version 6.13.3redhat · enterprise linux · CWE-61 | Средняя6,5 | — | 3,3 % | 12 дек. 2019 г. |
27Наблюдать | CVE-2019-16777Эксплойта нет | Arbitrary File Overwrite in npm CLInpmjs · npm · CWE-22 | Средняя6,5 | — | 2,1 % | 12 дек. 2019 г. |
22Наблюдать | CVE-2021-23362Эксплойта нет | Regular Expression Denial of Service (ReDoS)npmjs · hosted-git-info · CWE-1333 | Средняя5,3 | — | 3,6 % | 23 мар. 2021 г. |
17Наблюдать | CVE-2020-15095Эксплойта нет | Sensitive information exposure through logs in npm clinpmjs · npm · CWE-532 | Средняя4,4 | — | 0,4 % | 7 июл. 2020 г. |
- CVE-2021-4361640В плане
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differ
КритическаяCVSS 9,8Proof of conceptEPSS 3 %npmjs · npm13 нояб. 2021 г.
- CVE-2021-3770135Наблюдать
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
ВысокаяCVSS 8,6Эксплойта нетEPSS 3 %npmjs · tar31 авг. 2021 г.
- CVE-2021-3771235Наблюдать
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %npmjs · tar31 авг. 2021 г.
- CVE-2021-3771334Наблюдать
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %npmjs · tar31 авг. 2021 г.
- CVE-2019-1677633Наблюдать
Unauthorized File Access in npm CLI before before version 6.13.3
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %npmjs · npm12 дек. 2019 г.
- CVE-2016-395632Наблюдать
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %ibm · sdk2 июл. 2016 г.
- CVE-2022-2924431Наблюдать
npm packing does not respect root-level ignore files in workspaces
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %npmjs · npm13 июн. 2022 г.
- CVE-2020-775431Наблюдать
Regular Expression Denial of Service (ReDoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %npmjs · npm-user-validate27 окт. 2020 г.
- CVE-2022-2588331Наблюдать
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %npmjs · semver21 июн. 2023 г.
- CVE-2021-3913431Наблюдать
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %npmjs · arborist31 авг. 2021 г.
- CVE-2021-3913531Наблюдать
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %npmjs · arborist31 авг. 2021 г.
- CVE-2018-740831Наблюдать
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upg
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %npmjs · npm22 февр. 2018 г.
- CVE-2024-2152330Наблюдать
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fu
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %10 июл. 2024 г.
- CVE-2024-2535430Наблюдать
RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %27 мар. 2024 г.
- CVE-2019-1677527Наблюдать
Unauthorized File Access in npm CLI before before version 6.13.3
СредняяCVSS 6,5Эксплойта нетEPSS 3 %redhat · enterprise linux12 дек. 2019 г.
- CVE-2019-1677727Наблюдать
Arbitrary File Overwrite in npm CLI
СредняяCVSS 6,5Эксплойта нетEPSS 2 %npmjs · npm12 дек. 2019 г.
- CVE-2021-2336222Наблюдать
Regular Expression Denial of Service (ReDoS)
СредняяCVSS 5,3Эксплойта нетEPSS 4 %npmjs · hosted-git-info23 мар. 2021 г.
- CVE-2020-1509517Наблюдать
Sensitive information exposure through logs in npm cli
СредняяCVSS 4,4Эксплойта нетEPSS 0 %npmjs · npm7 июл. 2020 г.