CVE-2022-29244

high

Description

npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.

References

https://github.com/nodejs/node/pull/43210

https://github.com/nodejs/node/releases/tag/v16.15.1

https://github.com/nodejs/node/releases/tag/v17.9.1

https://github.com/nodejs/node/releases/tag/v18.3.0

https://github.com/npm/cli/releases/tag/v8.11.0

https://github.com/npm/cli/security/advisories/GHSA-hj9c-8jmm-8c52

https://github.com/npm/cli/tree/latest/workspaces/libnpmpack

https://github.com/npm/cli/tree/latest/workspaces/libnpmpublish

https://github.com/npm/npm-packlist

https://security.netapp.com/advisory/ntap-20220722-0007/

Details

Source: Mitre, NVD

Published: 2022-06-13

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High