CVE-2022-21704

EUVD-2022-0513
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
GitHub_MCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
log4js_projectlog4js
𝑥
< 6.4.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-log4js
bookworm
6.7.1+~cs8.4.17-1
fixed
bullseye
6.3.0+~cs8.3.10-1+deb11u1
fixed
sid
6.9.1+~cs8.4.19-1
fixed
trixie
6.9.1+~cs8.4.19-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-log4js
bionic
needs-triage
focal
needs-triage
impish
ignored
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
needs-triage