Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remediate High bin-links vulnerability #670

Open
Lilalamar opened this issue Jan 29, 2020 · 0 comments
Open

Remediate High bin-links vulnerability #670

Lilalamar opened this issue Jan 29, 2020 · 0 comments
Assignees
Labels
security Ticket concerns platform security

Comments

@Lilalamar
Copy link

Snyk reports the following High severity vulnerability in HumanCellAtlas/ingest-file-archiver. Please remediate by the end of Q1 Milestone 2.

Description
bin-links

Suggested Remediation
Upgrade bin-links to version 1.1.6 or higher.

Details
bin-links is a .bin/ script linker package. Affected versions of this package are vulnerable to Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the first binary. This only affects files in /usr/local/bin. For npm, this behaviour is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

@Lilalamar Lilalamar added the security Ticket concerns platform security label Jan 29, 2020
@Lilalamar Lilalamar added this to the Q1 2020 Milestone 2 milestone Jan 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Ticket concerns platform security
Projects
None yet
Development

No branches or pull requests

2 participants