Ukuba sengozini ku-NPM okuvumela amafayela angafanele ukuthi ashintshwe phakathi nokufakwa kwephakheji

Ekubuyekezweni komphathi wephakheji ye-NPM 6.13.4, efakwe ekusabalaliseni kwe-Node.js futhi esetshenziselwa ukusabalalisa amamojula ngolimi lwe-JavaScript, kuqedwe ubuthakathaka obuthathu (I-CVE-2019-16775, I-CVE-2019-16776 ΠΈ I-CVE-2019-16777), okuvumela amafayela esistimu ngokunganaki ukuthi ashintshwe noma abhalwe ngaphezulu lapho kufakwa iphakheji elilungiswe umhlaseli. Njengendlela yokuvikela, ungayifaka ngenketho ethi "-ignore-scripts", evimbela ukwenziwa kwamaphakheji esibambi akhelwe ngaphakathi. Abathuthukisi be-NPM bahlaziye amaphakheji atholakala endaweni yokugcina izinto futhi abatholanga mikhondo yezinkinga ezihlonziwe ezisetshenziselwa ukuhlasela.

  • I-CVE-2019-16777 liyavela ekukhishweni ngaphambi kuka-6.13.4 futhi ikuvumela ukuthi ubhale phezu kwamafayela asebenzisekayo esistimu phakathi nokufakwa kwephakheji yomhlaba wonke. Ungashintsha kuphela amafayela kunkomba eqondiwe lapho amafayela asebenzisekayo afakwa khona (ngokuvamile /usr/local/bin).
  • I-CVE-2019-16775 ΠΈ I-CVE-2019-16776 zivela kokukhishwayo ngaphambi komhla ka-6.13.3 futhi zikuvumela ukuthi ubhale ifayela elingenasizathu ngokwakha isixhumanisi esingokomfanekiso samafayela angaphandle kohlu lwemibhalo anamamojula (ama-node_modules) noma ngokukhohlisa inkambu yomgqomo ku-package.json (izindlela ezino-β€œ/../” kuvunyelwe endaweni yomgqomo).

    Source: opennet.ru

  • Engeza amazwana