npm CLI °²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2019-16776£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
npm CLI <= 6.13.3
·ì϶¸ÅÊö
npm CLIÊÇÒ»¿îÈí¼þ°üÖÎÀíÆ÷¡£
Npm ¿ª·¢ÈËÔ±°µÊ¾£¬npm ºÅÁîÐнçÃæ£¨CLI£©¿Í»§¶ËÊܵ½Á˰²È«·ì϶µÄÓ°Ï죬ͬʱÔ̺¬Îļþ±éÀúºÍËÁÒâÎļþ£¨¸²¸Ç£©Ð´ÈëÎÊÌâ¡£¹¥»÷ÕßÄܹ»ÀûÓøÃÃýÎóÀ´Ö²Èë¶ñÒâ¶þ½øÔìÎļþ»ò¸²¸ÇÓû§ÍÆËã»úÉϵÄÎļþ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46
²Î¿¼Á´½Ó
https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/


¾©¹«Íø°²±¸11010802024551ºÅ