Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-21704
HistoryJan 19, 2022 - 12:00 a.m.

CVE-2022-21704 Incorrect Default Permissions in log4js-node

2022-01-1900:00:00
CWE-276
GitHub_M
www.cve.org
8
cve-2022-21704
log4js-node
node.js
default permissions
log files
world-readable
sensitive information
update

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

17.3%

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.

CNA Affected

[
  {
    "vendor": "log4js-node",
    "product": "log4js-node",
    "versions": [
      {
        "version": "< 6.4.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

17.3%