Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22162
HistoryDec 12, 2019 - 3:16 a.m.

Arbitrary File Overwrite

2019-12-1203:16:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.001

Percentile

44.1%

npm is vulnerable to arbitrary file overwrite. The package does not prevent existing globally-installed binaries from being overwritten by other package installations in /usr/local/bin. This would allow the overwriting of binary files created from the first installation.