CVE-2019-16777

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
npmjsnpm
𝑥
< 6.13.4
opensuseleap
15.1
oraclegraalvm
19.3.0.2
redhatenterprise_linux
8.0
redhatenterprise_linux_eus
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
npm
bookworm
9.2.0~ds1-1
fixed
bullseye
7.5.2+ds-2
fixed
sid
9.2.0~ds1-3
fixed
trixie
9.2.0~ds1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
npm
bionic
needs-triage
disco
ignored
eoan
ignored
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs10
suse enterprise sap 15
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP1
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP2
10.18.0-1.15.1
fixed
suse enterprise server 15
10.18.0-1.15.1
fixed
suse enterprise server 15 SP1
10.18.0-1.15.1
fixed
suse enterprise server 15 SP2
10.18.0-1.15.1
fixed
nodejs10-devel
suse enterprise sap 15
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP1
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP2
10.18.0-1.15.1
fixed
suse enterprise server 15
10.18.0-1.15.1
fixed
suse enterprise server 15 SP1
10.18.0-1.15.1
fixed
suse enterprise server 15 SP2
10.18.0-1.15.1
fixed
nodejs10-docs
suse enterprise sap 15
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP1
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP2
10.18.0-1.15.1
fixed
suse enterprise server 15
10.18.0-1.15.1
fixed
suse enterprise server 15 SP1
10.18.0-1.15.1
fixed
suse enterprise server 15 SP2
10.18.0-1.15.1
fixed
nodejs8
suse enterprise sap 15
8.17.0-3.25.1
fixed
suse enterprise sap 15 SP1
8.17.0-3.25.1
fixed
suse enterprise server 15
8.17.0-3.25.1
fixed
suse enterprise server 15 SP1
8.17.0-3.25.1
fixed
nodejs8-devel
suse enterprise sap 15
8.17.0-3.25.1
fixed
suse enterprise sap 15 SP1
8.17.0-3.25.1
fixed
suse enterprise server 15
8.17.0-3.25.1
fixed
suse enterprise server 15 SP1
8.17.0-3.25.1
fixed
nodejs8-docs
suse enterprise sap 15
8.17.0-3.25.1
fixed
suse enterprise sap 15 SP1
8.17.0-3.25.1
fixed
suse enterprise server 15
8.17.0-3.25.1
fixed
suse enterprise server 15 SP1
8.17.0-3.25.1
fixed
npm10
suse enterprise sap 15
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP1
10.18.0-1.15.1
fixed
suse enterprise sap 15 SP2
10.18.0-1.15.1
fixed
suse enterprise server 15
10.18.0-1.15.1
fixed
suse enterprise server 15 SP1
10.18.0-1.15.1
fixed
suse enterprise server 15 SP2
10.18.0-1.15.1
fixed
npm8
suse enterprise sap 15
8.17.0-3.25.1
fixed
suse enterprise sap 15 SP1
8.17.0-3.25.1
fixed
suse enterprise server 15
8.17.0-3.25.1
fixed
suse enterprise server 15 SP1
8.17.0-3.25.1
fixed