npmjs kayıtları
npmjs üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %88,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-61 UNIX Symbolic Link (Symlink) Following3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-1333 Inefficient Regular Expression Complexity2
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-345 Insufficient Verification of Data Authenticity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-43616Kavram kanıtı | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differnpmjs · npm · CWE-345 | Kritik9,8 | — | %2,7 | 13 Kas 2021 |
35İzleyin | CVE-2021-37701İstismar yok | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linksnpmjs · tar · CWE-22 | Yüksek8,6 | — | %3,3 | 31 Ağu 2021 |
35İzleyin | CVE-2021-37712İstismar yok | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linksnpmjs · tar · CWE-22 | Yüksek8,6 | — | %1,9 | 31 Ağu 2021 |
34İzleyin | CVE-2021-37713İstismar yok | Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitizationnpmjs · tar · CWE-22 | Yüksek8,6 | — | %1,3 | 31 Ağu 2021 |
33İzleyin | CVE-2019-16776İstismar yok | Unauthorized File Access in npm CLI before before version 6.13.3npmjs · npm · CWE-22 | Yüksek8,1 | — | %3,4 | 12 Ara 2019 |
32İzleyin | CVE-2016-3956İstismar yok | The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 beforeibm · sdk · CWE-200 | Yüksek7,5 | — | %6,7 | 2 Tem 2016 |
31İzleyin | CVE-2022-29244İstismar yok | npm packing does not respect root-level ignore files in workspacesnpmjs · npm · CWE-200 | Yüksek7,5 | — | %3,9 | 13 Haz 2022 |
31İzleyin | CVE-2020-7754İstismar yok | Regular Expression Denial of Service (ReDoS)npmjs · npm-user-validate | Yüksek7,5 | — | %3,5 | 27 Eki 2020 |
31İzleyin | CVE-2022-25883İstismar yok | Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when npmjs · semver · CWE-1333 | Yüksek7,5 | — | %2,8 | 21 Haz 2023 |
31İzleyin | CVE-2021-39134İstismar yok | UNIX Symbolic Link (Symlink) Following in @npmcli/arboristnpmjs · arborist · CWE-61 | Yüksek7,8 | — | %0,6 | 31 Ağu 2021 |
31İzleyin | CVE-2021-39135İstismar yok | UNIX Symbolic Link (Symlink) Following in @npmcli/arboristnpmjs · arborist · CWE-61 | Yüksek7,8 | — | %0,6 | 31 Ağu 2021 |
31İzleyin | CVE-2018-7408İstismar yok | An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgnpmjs · npm · CWE-732 | Yüksek7,8 | — | %0,3 | 22 Şub 2018 |
30İzleyin | CVE-2024-21523İstismar yok | All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fuCWE-400 | Yüksek7,5 | — | %0,6 | 10 Tem 2024 |
30İzleyin | CVE-2024-25354İstismar yok | RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function. | Yüksek7,5 | — | %0,6 | 27 Mar 2024 |
27İzleyin | CVE-2019-16775İstismar yok | Unauthorized File Access in npm CLI before before version 6.13.3redhat · enterprise linux · CWE-61 | Orta6,5 | — | %3,3 | 12 Ara 2019 |
27İzleyin | CVE-2019-16777İstismar yok | Arbitrary File Overwrite in npm CLInpmjs · npm · CWE-22 | Orta6,5 | — | %2,1 | 12 Ara 2019 |
22İzleyin | CVE-2021-23362İstismar yok | Regular Expression Denial of Service (ReDoS)npmjs · hosted-git-info · CWE-1333 | Orta5,3 | — | %3,6 | 23 Mar 2021 |
17İzleyin | CVE-2020-15095İstismar yok | Sensitive information exposure through logs in npm clinpmjs · npm · CWE-532 | Orta4,4 | — | %0,4 | 7 Tem 2020 |
- CVE-2021-4361640Planlayın
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differ
KritikCVSS 9,8Kavram kanıtıEPSS %3npmjs · npm13 Kas 2021
- CVE-2021-3770135İzleyin
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
YüksekCVSS 8,6İstismar yokEPSS %3npmjs · tar31 Ağu 2021
- CVE-2021-3771235İzleyin
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
YüksekCVSS 8,6İstismar yokEPSS %2npmjs · tar31 Ağu 2021
- CVE-2021-3771334İzleyin
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
YüksekCVSS 8,6İstismar yokEPSS %1npmjs · tar31 Ağu 2021
- CVE-2019-1677633İzleyin
Unauthorized File Access in npm CLI before before version 6.13.3
YüksekCVSS 8,1İstismar yokEPSS %3npmjs · npm12 Ara 2019
- CVE-2016-395632İzleyin
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before
YüksekCVSS 7,5İstismar yokEPSS %7ibm · sdk2 Tem 2016
- CVE-2022-2924431İzleyin
npm packing does not respect root-level ignore files in workspaces
YüksekCVSS 7,5İstismar yokEPSS %4npmjs · npm13 Haz 2022
- CVE-2020-775431İzleyin
Regular Expression Denial of Service (ReDoS)
YüksekCVSS 7,5İstismar yokEPSS %3npmjs · npm-user-validate27 Eki 2020
- CVE-2022-2588331İzleyin
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when
YüksekCVSS 7,5İstismar yokEPSS %3npmjs · semver21 Haz 2023
- CVE-2021-3913431İzleyin
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
YüksekCVSS 7,8İstismar yokEPSS %1npmjs · arborist31 Ağu 2021
- CVE-2021-3913531İzleyin
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
YüksekCVSS 7,8İstismar yokEPSS %1npmjs · arborist31 Ağu 2021
- CVE-2018-740831İzleyin
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upg
YüksekCVSS 7,8İstismar yokEPSS %0npmjs · npm22 Şub 2018
- CVE-2024-2152330İzleyin
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different fu
YüksekCVSS 7,5İstismar yokEPSS %110 Tem 2024
- CVE-2024-2535430İzleyin
RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.
YüksekCVSS 7,5İstismar yokEPSS %127 Mar 2024
- CVE-2019-1677527İzleyin
Unauthorized File Access in npm CLI before before version 6.13.3
OrtaCVSS 6,5İstismar yokEPSS %3redhat · enterprise linux12 Ara 2019
- CVE-2019-1677727İzleyin
Arbitrary File Overwrite in npm CLI
OrtaCVSS 6,5İstismar yokEPSS %2npmjs · npm12 Ara 2019
- CVE-2021-2336222İzleyin
Regular Expression Denial of Service (ReDoS)
OrtaCVSS 5,3İstismar yokEPSS %4npmjs · hosted-git-info23 Mar 2021
- CVE-2020-1509517İzleyin
Sensitive information exposure through logs in npm cli
OrtaCVSS 4,4İstismar yokEPSS %0npmjs · npm7 Tem 2020