CVE-2022-21704
Incorrect Default Permissions in log4js-node
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
19 ene 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
log4js-node · log4js-node¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/log4js-node/log4js-node/blob/v6.4.0/CHANGELOG.md#640https://github.com/log4js-node/log4js-node/pull/1141/commits/8042252861a1b65adb66931fdf702ead34fa9b76https://github.com/log4js-node/log4js-node/security/advisories/GHSA-82v2-mx6x-wq7qhttps://github.com/log4js-node/streamroller/pull/87https://lists.debian.org/debian-lts-announce/2022/12/msg00014.html