Snynet Solution Logo
MON - SUN: 10 AM - 6 PM
+60 11 5624 8319

Blog

GitHub identifies multiple nasty security vulnerabilities

Image Description

Cybersecurity researchers have identified just over half a dozen vulnerabilities in a couple of npm packages, which can be exploited by attackers to execute arbitrary code on systems that permit installation of untrusted npm packages.

The vulnerabilities were identified thanks to the initial reports by bug bounty hunters Robert Chen and Philip Papurt, who found security issues in the tar and @npmcli/arborist packages.

Further review of their reports led the GitHub security team to find a handful of other high-severity vulnerabilities in these cross-platform packages.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window

“When we learned of these vulnerabilities, we immediately started working on fixes and began scanning the npm registry for malicious packages that may have directly targeted the vulnerability that affected all npm CLI platforms,” shares GitHub’s Chief Security Officer Michael Hanley.

The scan completed early in August with the team failing to find any malicious packages that take advantage of the vulnerabilities.

Update your dependencies

Although exploitation of the issues through the npn CLI requires the installation of untrusted packages or processing untrusted tar archives, Hanley still urges developers to upgrade to the latest version of the affected utilities.

Developers with projects that depend on tar should ensure they upgrade their tar dependency versions to v4.4.19, v5.0.11, or v6.1.10, or newer. 

Similarly, for npm CLI, Hanley advises users to move to v6.14.15, v7.21.0, or newer, which  contain the fix. 

“If you rely on Node.js for your npm installation, please update to the latest version of Node.js. The latest releases of Node 12, 14, and 16 as of August 31, 2021 all contain patched versions of npm that prevent exploitation,” writes Hanley.

Date

09 Sep 2021

Sources


Share


Other Blog

  • Exclusive: Next-gen 36TB tape will land sooner rather than later

    The LTO Program has revealed it intends to return to its traditional release cycle.

    Read More
  • Cheap Chromebooks could get price rises thanks to supply issues

    Problems with the supply of eMMC storage may usher in price hikes.

    Read More
  • The best cheap laptop deals in November 2020

    We're rounding up all the latest cheap laptop deals in the US right here so you can grab the best budget laptop for less.

    Read More
  • Square takes on major banks with new suite of financial services for your business

    New financial products designed to work seamlessly together under the Square banner.

    Read More

Find Out More About Us

Want to hire best people for your project? Look no further you came to the right place!

Contact Us