CVE-2018-7408

An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's blog without mention of pre-release status). It might allow local users to bypass intended filesystem access restrictions because ownerships of /etc and /usr directories are being changed unexpectedly, related to a "correctMkdir" issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
npmjsnpm
5.7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
npm
bullseye
7.5.2+ds-2
fixed
bookworm
9.2.0~ds1-1
fixed
sid
9.2.0~ds1-3
fixed
trixie
9.2.0~ds1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
npm
cosmic
not-affected
bionic
not-affected
artful
ignored
xenial
not-affected
trusty
not-affected