Upstream information

CVE-2024-37150 at MITRE

Description

An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain. All users relying on .npmrc are potentially affected by this vulnerability if their private registry references tarball URLs at a different domain. This includes usage of deno install subcommand, auto-install for npm: specifiers and LSP usage. It is recommended to upgrade to Deno 1.44.1 and if your private registry ever serves tarballs at a different domain to rotate your registry credentials.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v3 Scores
  CNA (GitHub) National Vulnerability Database SUSE
Base Score 7.6 6.5 6.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector Network Network Network
Attack Complexity Low Low Low
Privileges Required None None None
User Interaction Required Required Required
Scope Unchanged Unchanged Unchanged
Confidentiality Impact High High High
Integrity Impact Low None None
Availability Impact Low None None
CVSSv3 Version 3.1 3.1 3.1
SUSE Bugzilla entry: 1226058 [RESOLVED / INVALID]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Thu Jun 6 20:00:04 2024
CVE page last modified: Thu Sep 26 21:50:07 2024