VulnerabilityModified
CVE-2019-5484
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
HIGH 7.5EPSS 2.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- bower/bower
- Source
- support@hackerone.com
References
- https://github.com/bower/bower/commit/45c6bfa86f6e57731b153baca9e0b41a1cc699e3Patch
- https://hackerone.com/reports/473811Exploit, Patch, Third Party Advisory
- https://lists.apache.org/thread.html/r8ba4c628fba7181af58817d452119481adce4ba92e889c643e4c7dd3%40%3Ccommits.netbeans.apache.org%3E
- https://lists.apache.org/thread.html/rb5ac16fad337d1f3bb7079549f97d8166d0ef3082629417c39f12d63%40%3Cnotifications.netbeans.apache.org%3E
- https://snyk.io/blog/severe-security-vulnerability-in-bowers-zip-archive-extractionExploit, Third Party Advisory
- https://github.com/bower/bower/commit/45c6bfa86f6e57731b153baca9e0b41a1cc699e3Patch
- https://hackerone.com/reports/473811Exploit, Patch, Third Party Advisory
- https://lists.apache.org/thread.html/r8ba4c628fba7181af58817d452119481adce4ba92e889c643e4c7dd3%40%3Ccommits.netbeans.apache.org%3E
- https://lists.apache.org/thread.html/rb5ac16fad337d1f3bb7079549f97d8166d0ef3082629417c39f12d63%40%3Cnotifications.netbeans.apache.org%3E
- https://snyk.io/blog/severe-security-vulnerability-in-bowers-zip-archive-extractionExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.