ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ NPM ืึทื– ืึทืœืึทื•ื– ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื˜ืขืงืขืก ืฆื• ื–ื™ื™ืŸ ืžืึทื“ืึทืคื™ื™ื“ ื‘ืขืฉืึทืก ืคึผืขืงืœ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’

ืื™ืŸ ื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืคื•ืŸ ื“ื™ NPM 6.13.4 ืคึผืขืงืœ ืคืึทืจื•ื•ืึทืœื˜ืขืจ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ Node.js ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืื•ืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืคืึทืจืฉืคึผืจื™ื™ื˜ืŸ ืžืึทื“ื–ืฉื•ืœื– ืื™ืŸ ื“ื™ ื“ื–ืฉืึทื•ื•ืึทืกืงืจื™ืคึผื˜ ืฉืคึผืจืึทืš, ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ื“ืจื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2019-16775, CVE-2019-16776 ะธ CVE-2019-16777), ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืกื™ืกื˜ืขื ื˜ืขืงืขืก ืฆื• ื–ื™ื™ืŸ ืžืึทื“ืึทืคื™ื™ื“ ืึธื“ืขืจ ืึธื•ื•ื•ืขืจืจื™ื˜ืึทืŸ ื•ื•ืขืŸ ื™ื ืกื˜ืึธืœื™ื ื’ ืึท ืคึผืขืงืœ ืฆื•ื’ืขื’ืจื™ื™ื˜ ื“ื•ืจืš ืึท ืึทื˜ืึทืงืขืจ. ื•ื•ื™ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“ ืคึฟืึทืจ ืฉื•ืฅ, ืื™ืจ ืงืขื ืขืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืขืก ืžื™ื˜ ื“ื™ "-ื™ื’ื ืึธืจืข-ืกืงืจื™ืคึผืก" ืึธืคึผืฆื™ืข, ื•ื•ืึธืก ืคึผืจืึธื•ื›ื™ื‘ืึทืฅ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ื”ืึทื ื“ืœืขืจ ืคึผืึทืงืึทื“ื–ืฉืึทื–. NPM ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืึทื ืึทืœื™ื™ื–ื“ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื– ื‘ื ื™ืžืฆื ืื™ืŸ ื“ื™ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ ืื•ืŸ ื’ืขืคื•ื ืขืŸ ืงื™ื™ืŸ ื˜ืจืึทืกืขืก ืคื•ืŸ ื“ื™ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืคึผืจืึธื‘ืœืขืžืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืื ืคืืœืŸ.

  • CVE-2019-16777 ืื•ื™ืก ืื™ืŸ ืจื™ืœื™ืกื™ื– ืื™ื™ื“ืขืจ 6.13.4 ืื•ืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืึธื•ื•ื•ืขืจืจื™ื™ื˜ ืกื™ืกื˜ืขื ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืขืก ื‘ืขืฉืึทืก ื’ืœืื‘ืืœืข ืคึผืขืงืœ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ืื™ืจ ืงืขื ืขืŸ ื‘ืœื•ื™ื– ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื˜ืขืงืขืก ืื™ืŸ ื“ื™ ืฆื™ืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื•ื•ื• ื“ื™ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืขืก ื–ืขื ืขืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ (ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ /usr/local/bin).
  • CVE-2019-16775 ะธ CVE-2019-16776 ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ืจื™ืœื™ืกื™ื– ืื™ื™ื“ืขืจ 6.13.3 ืื•ืŸ ืœืึธื–ืŸ ืื™ืจ ืฆื• ืฉืจื™ื™ึทื‘ืŸ ืึท ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื˜ืขืงืข ื“ื•ืจืš ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืกื™ืžื‘ืึธืœื™ืฉ ืœื™ื ืง ืฆื• ื˜ืขืงืขืก ืึทืจื•ื™ืก ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืžื™ื˜ ืžืึทื“ื–ืฉื•ืœื– (ื ืึธื“ืข_ืžืึธื“ื•ืœืขืก) ืึธื“ืขืจ ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ื˜ื™ื ื’ ื“ื™ bin field ืื™ืŸ package.json (ืคึผืึทื˜ืก ืžื™ื˜ "/../" ื–ืขื ืขืŸ ื’ืขื•ื•ืขืŸ ืขืจืœื•ื™ื‘ื˜ ืื™ืŸ ื“ื™ ื‘ืึทืŸ ืคืขืœื“).

    ืžืงื•ืจ: opennet.ru

  • ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’