{"id":"GHSA-38h8-x697-gh8q","summary":"Tmp files readable by other users in sync-exec","details":"Affected versions of `sync-exec` use files located in `/tmp/` to buffer command results before returning values. As `/tmp/` is almost always set with world readable permissions, this may allow low privilege users on the system to read the results of commands run via `sync-exec` under a higher privilege user.\n\n\n## Recommendation\n\nThere is currently no direct patch for `sync-exec`, as the `child_process.execSync` function provided in Node.js v0.12.0 and later provides the same functionality natively. \n\nThe best mitigation currently is to update to Node.js v0.12.0 or later, and migrate all uses of `sync-exec` to `child_process.execSync()`.","aliases":["CVE-2017-16024"],"modified":"2023-11-08T03:59:00.317387Z","published":"2018-11-09T17:45:30Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T20:54:36Z","nvd_published_at":null,"cwe_ids":["CWE-377"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16024"},{"type":"WEB","url":"https://github.com/gvarsanyi/sync-exec/issues/17"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/377.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38h8-x697-gh8q"},{"type":"WEB","url":"https://www.npmjs.com/advisories/310"},{"type":"WEB","url":"https://www.owasp.org/index.php/Insecure_Temporary_File"}],"affected":[{"package":{"name":"sync-exec","ecosystem":"npm","purl":"pkg:npm/sync-exec"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-38h8-x697-gh8q/GHSA-38h8-x697-gh8q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}