First published: Mon Jun 13 2022(Updated: )
A flaw was found in npm. This security issue occurs because the npm pack ignores root-level ".gitignore" and ".npmignore" file exclusion directives when run in a workspace or with a workspace flag (for example, --workspaces, --workspace=<name>). Anyone who has run 'npm pack' or 'npm publish' inside a workspace has published files into the npm registry they did not intend to include. This flaw exposes sensitive information to an unauthorized user or an attacker.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nodejs | <1:16.16.0-1.el9_0 | 1:16.16.0-1.el9_0 |
Npmjs Npm | >=7.9.0<8.11.0 | |
NetApp ONTAP Select Deploy administration utility |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29244 is a security vulnerability in npm that allows ignoring certain exclusion directives.
The security issue in CVE-2022-29244 occurs because npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag.
Anyone who has run npm pack or npm publish inside a workspace may be affected by CVE-2022-29244.
The severity of CVE-2022-29244 is high with a CVSS score of 7.5.
To fix CVE-2022-29244, update Node.js to version 16.15.1, 17.19.1, or 18.3.0, or update the nodejs package to version 1:16.16.0-1.el9_0.