npm CLI Çå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-16Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£º CVE-2019-16776£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
npm CLI <= 6.13.3
Îó²î¸ÅÊö
npm CLIÊÇÒ»¿îÈí¼þ°ü¹ÜÀíÆ÷¡£¡£¡£
Npm ¿ª·¢Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬npm ÏÂÁîÐнçÃæ£¨CLI£©¿Í»§¶ËÊܵ½ÁËÇå¾²Îó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬Í¬Ê±°üÀ¨Îļþ±éÀúºÍí§ÒâÎļþ£¨ÁýÕÖ£©Ð´ÈëÎÊÌâ¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøùýʧÀ´Ö²Èë¶ñÒâ¶þ½øÖÆÎļþ»òÁýÕÖÓû§ÅÌËã»úÉϵÄÎļþ¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46
²Î¿¼Á´½Ó
https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/


¾©¹«Íø°²±¸11010802024551ºÅ