{"id":101233,"date":"2021-09-09T10:22:51","date_gmt":"2021-09-09T08:22:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme"},"modified":"2021-09-09T10:22:51","modified_gmt":"2021-09-09T08:22:51","slug":"uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme","title":{"rendered":"O vulnerabilitate \u00een NPM, care duce la suprascrierea fi\u0219ierelor \u00een sistem","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Compania GitHub a dezv\u0103luit detalii despre \u0219apte vulnerabilit\u0103\u021bi \u00een pachetele tar \u0219i @npmcli\/arborist, care ofer\u0103 func\u021bii pentru manipularea arhivelor tar \u0219i calculul arborelui de dependen\u021be \u00een Node.js. Vulnerabilit\u0103\u021bile permit, la extragerea unei arhive special concepute, suprascrierea fi\u0219ierelor din afara directorului r\u0103d\u0103cin\u0103 \u00een care se face extragerea, \u00een m\u0103sura \u00een care permisiunile curente permit acest lucru. Problemele permit executarea de cod arbitrar \u00een sistem, de exemplu, prin ad\u0103ugarea de comenzi \u00een ~\/.bashrc sau ~\/.profile atunci c\u00e2nd opera\u021bia este efectuat\u0103 de un utilizator f\u0103r\u0103 privilegii sau prin \u00eenlocuirea fi\u0219ierelor de sistem atunci c\u00e2nd se ruleaz\u0103 cu privilegii root.    <\/p>\n<p>Pericolul vulnerabilit\u0103\u021bilor este agravat de faptul c\u0103 codul problematic este utilizat \u00een managerul de pachete npm, \u00een opera\u021biunile cu pachetele npm, ceea ce permite organizarea unei atacuri asupra utilizatorilor prin plasarea unui pachet npm special conceput \u00een depozit, la procesarea c\u0103ruia codul atacatorului va fi executat \u00een sistem. Atacul este posibil chiar \u0219i atunci c\u00e2nd pachetele sunt instalate \u00een modul &#171;&#8212;ignore-scripts&#187;, care dezactiveaz\u0103 execu\u021bia scripturilor integrate. \u00cen total, npm afecteaz\u0103 patru vulnerabilit\u0103\u021bi (CVE-2021-32804, CVE-2021-37713, CVE-2021-39134 \u0219i CVE-2021-39135) din \u0219apte. Primele dou\u0103 probleme se refer\u0103 la pachetul tar, iar celelalte dou\u0103 la pachetul @npmcli\/arborist.    <\/p>\n<p>Cea mai periculoas\u0103 vulnerabilitate CVE-2021-32804 este cauzat\u0103 de faptul c\u0103, la cur\u0103\u021barea c\u0103ilor absolute specificate \u00een arhiva tar, simbolurile repetitive &#171; \/ &#187; sunt procesate incorect - este eliminat doar primul simbol, iar restul sunt l\u0103sate. De exemplu, calea &#171;\/home\/user\/.bashrc&#187; va fi transformat\u0103 \u00een &#171;home\/user\/.bashrc&#187;, iar calea &#171;\/\/home\/user\/.bashrc&#187; \u00een &#171;\/home\/user\/.bashrc&#187;. A doua vulnerabilitate, CVE-2021-37713, se manifest\u0103 doar pe platforma Windows \u0219i este legat\u0103 de cur\u0103\u021barea incorect\u0103 a c\u0103ilor relative, care includ un simbol de disc nedivizat (&#171;C:some\textbackslash path&#187;) \u0219i o secven\u021b\u0103 pentru a reveni la directorul anterior (&#171;C:..\/foo&#187;).     <\/p>\n<p>Vulnerabilit\u0103\u021bile CVE-2021-39134 \u0219i CVE-2021-39135 sunt specifice modulului @npmcli\/arborist. Prima problem\u0103 se manifest\u0103 doar pe sistemele care nu difer\u0103 \u00eentre majuscule \u0219i minuscule \u00een FS (macOS \u0219i Windows) \u0219i permite scrierea de fi\u0219iere \u00eentr-o parte arbitrar\u0103 a FS, specific\u00e2nd \u00een num\u0103rul de dependen\u021be dou\u0103 module &#8216;&#187;foo&#187;: &#171;file:\/some\/path&#187;&#8216; \u0219i &#8216;FOO: &#171;file:foo.tgz&#187;&#8216;, procesarea c\u0103rora va duce la \u0219tergerea con\u021binutului directorului \/some\/path \u0219i la scrierea \u00een el a con\u021binutului foo.tgz. A doua problem\u0103 permite scrierea asupra fi\u0219ierelor prin manipularea cu linkuri simbolice.         <\/p>\n<p>Vulnerabilit\u0103\u021bile au fost remediate \u00een versiunile Node.js 12.22.6 \u0219i 14.17.6, npm CLI 6.14.15 \u0219i 7.21.0, precum \u0219i \u00een versiunile individuale ale pachetului tar 4.4.19, 5.0.11 \u0219i 6.1.10. Dup\u0103 ce a primit informa\u021bii despre problem\u0103 \u00een cadrul ini\u021biativei &#171;bug bounty&#187;, GitHub a pl\u0103tit cercet\u0103torilor 14.500$ \u0219i a scanat con\u021binutul depozitului, \u00een care nu au fost identificate \u00eencerc\u0103ri de exploatare a vulnerabilit\u0103\u021bilor. Pentru a se proteja \u00eempotriva problemelor men\u021bionate, GitHub a impus, de asemenea, interdic\u021bia de a publica \u00een depozitul NPM pachete care includ linkuri simbolice, linkuri dure \u0219i c\u0103i absolute.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55767\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f GitHub \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043e \u0441\u0435\u043c\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 tar \u0438 @npmcli\/arborist, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 tar-\u0430\u0440\u0445\u0438\u0432\u0430\u043c\u0438 \u0438 \u0440\u0430\u0441\u0447\u0435\u0442\u0430 \u0434\u0435\u0440\u0435\u0432\u0430 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 Node.js. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0430\u0440\u0445\u0438\u0432\u0430 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u0430\u043c\u0438 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0433\u043e \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0430, \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u044d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0442\u0435\u043a\u0443\u0449\u0438\u0435 \u043f\u0440\u0430\u0432\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-101233","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f GitHub \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043e \u0441\u0435\u043c\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 tar \u0438 @npmcli\/arborist, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 tar-\u0430\u0440\u0445\u0438\u0432\u0430\u043c\u0438 \u0438 \u0440\u0430\u0441\u0447\u0435\u0442\u0430 \u0434\u0435\u0440\u0435\u0432\u0430 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 Node.js.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 NPM, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0438 \u0444\u0430\u0439\u043b\u043e\u0432 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f GitHub \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043e \u0441\u0435\u043c\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 tar \u0438 @npmcli\/arborist, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 tar-\u0430\u0440\u0445\u0438\u0432\u0430\u043c\u0438 \u0438 \u0440\u0430\u0441\u0447\u0435\u0442\u0430 \u0434\u0435\u0440\u0435\u0432\u0430 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 Node.js.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-09-09T08:22:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-09-09T08:22:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een NPM care duce la suprascrierea fi\u0219ierelor \u00een sistem | ProHoster","description":"Compania GitHub a dezv\u0103luit detalii despre \u0219apte vulnerabilit\u0103\u021bi \u00een pachetele tar \u0219i @npmcli\/arborist, care ofer\u0103 func\u021bii pentru lucrul cu arhive tar \u0219i calculul arborelui de dependen\u021be \u00een Node.js.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 NPM, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0438 \u0444\u0430\u0439\u043b\u043e\u0432 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f GitHub \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0430 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u043e\u0441\u0442\u0438 \u043e \u0441\u0435\u043c\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 tar \u0438 @npmcli\/arborist, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0438\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 tar-\u0430\u0440\u0445\u0438\u0432\u0430\u043c\u0438 \u0438 \u0440\u0430\u0441\u0447\u0435\u0442\u0430 \u0434\u0435\u0440\u0435\u0432\u0430 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 Node.js.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-npm-privodyashhaya-k-perezapisi-fajlov-v-sisteme","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-09-09T08:22:51+00:00","article:modified_time":"2021-09-09T08:22:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"101233","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-09-09 08:26:02","updated":"2022-09-27 22:52:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/101233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=101233"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/101233\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=101233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=101233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=101233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}