ืคื’ื™ืขื•ืช ื‘-NPM ื”ืžืืคืฉืจืช ืœืฉื ื•ืช ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืžื”ืœืš ื”ืชืงื ืช ื”ื—ื‘ื™ืœื”

ื‘ืขื“ื›ื•ืŸ ืฉืœ ืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช NPM 6.13.4, ื”ื ื›ืœืœ ื‘ื”ืคืฆืช Node.js ื•ืžืฉืžืฉ ืœื”ืคืฆืช ืžื•ื“ื•ืœื™ื ื‘ืฉืคืช JavaScript, ื—ื•ืกืœื• ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” (CVE-2019-16775, CVE-2019-16776 ะธ CVE-2019-16777), ื”ืžืืคืฉืจ ืœืฉื ื•ืช ืื• ืœื“ืจื•ืก ืงื‘ืฆื™ ืžืขืจื›ืช ืฉืจื™ืจื•ืชื™ื™ื ื‘ืขืช ื”ืชืงื ืช ื—ื‘ื™ืœื” ืฉื”ื•ื›ื ื” ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื”ื’ื ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืชืงื™ืŸ ืื•ืชื• ืขื ืืคืฉืจื•ืช "-ignore-scripts", ื”ืื•ืกืจืช ืขืœ ื‘ื™ืฆื•ืข ื—ื‘ื™ืœื•ืช ืžื˜ืคืœ ืžื•ื‘ื ื•ืช. ืžืคืชื—ื™ NPM ื ื™ืชื—ื• ืืช ื”ื—ื‘ื™ืœื•ืช ื”ื–ืžื™ื ื•ืช ื‘ืžืื’ืจ ื•ืœื ืžืฆืื• ืขืงื‘ื•ืช ืœื‘ืขื™ื•ืช ืฉื–ื•ื”ื• ื‘ืฉื™ืžื•ืฉ ืœื‘ื™ืฆื•ืข ื”ืชืงืคื•ืช.

  • CVE-2019-16777 ืžื•ืคื™ืข ื‘ืžื”ื“ื•ืจื•ืช ืœืคื ื™ 6.13.4 ื•ืžืืคืฉืจืช ืœืš ืœื”ื—ืœื™ืฃ ืงื‘ืฆื™ ื”ืคืขืœื” ืฉืœ ื”ืžืขืจื›ืช ื‘ืžื”ืœืš ื”ืชืงื ืช ื—ื‘ื™ืœื” ื’ืœื•ื‘ืœื™ืช. ืืชื” ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ ืงื‘ืฆื™ื ืจืง ื‘ืกืคืจื™ื™ืช ื”ื™ืขื“ ืฉื‘ื” ืžื•ืชืงื ื™ื ืงื‘ืฆื™ ื”ื”ืคืขืœื” (ื‘ื“ืจืš ื›ืœืœ /usr/local/bin).
  • CVE-2019-16775 ะธ CVE-2019-16776 ืžื•ืคื™ืขื™ื ื‘ืžื”ื“ื•ืจื•ืช ืœืคื ื™ 6.13.3 ื•ืžืืคืฉืจื™ื ืœืš ืœื›ืชื•ื‘ ืงื•ื‘ืฅ ืฉืจื™ืจื•ืชื™ ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืงื™ืฉื•ืจ ืกืžืœื™ ืœืงื‘ืฆื™ื ืžื—ื•ืฅ ืœืกืคืจื™ื™ื” ืขื ืžื•ื“ื•ืœื™ื (node_modules) ืื• ืขืœ ื™ื“ื™ ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืฉื“ื” ื”-bin ื‘-package.json (ื ืชื™ื‘ื™ื ืขื "/../" ื”ื™ื• ืžื•ืชืจ ื‘ืฉื“ื” ื”ืคื—).

    ืžืงื•ืจ: OpenNet.ru

  • ื”ื•ืกืคืช ืชื’ื•ื‘ื”