CVE-2016-3956
published 2016-07-02CVE-2016-3956: The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
6.75%
93.2th percentile
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
Affected
96 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | npm | < npm 5.8.0+ds-2 (bookworm) | npm 5.8.0+ds-2 (bookworm) |
| ibm | sdk | <= 1.1.0.20 | — |
| ibm | sdk | <= 1.2.0.10 | — |
| ibm | sdk | <= 4.4.1.0 | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
npm vulnerability
vendor_ubuntu·2021-03-15
CVE-2016-3956 npm vulnerability
Title: npm vulnerability
Summary: npm could be made to expose sensitive information.
It was discovered that the npm command-line interface mishandled certain
sensitive information. An attacker could use this vulnerability to collect
authentication information that could be used to impersonate other users.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
npm: bearer token leak to non-registry hosts
vendor_redhat·2016-03-31·CVSS 7.5
CVE-2016-3956 [HIGH] CWE-201 npm: bearer token leak to non-registry hosts
npm: bearer token leak to non-registry hosts
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
Package: nodejs010-npm (Red Hat Software Collections) - Will not fix
Package: rh-nodejs4-npm (Red Hat Software Collections) - Not affected
Debian
CVE-2016-3956: npm - The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 befor...
vendor_debian·2016·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956: npm - The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 befor...
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
Scope: local
bookworm: resolved (fixed in 5.8.0+ds-2)
bullseye: resolved (fixed in 5.8.0+ds-2)
forky: resolved (fixed in 5.8.0+ds-2)
sid: resolved (fixed in 5.8.0+ds-2)
trixie: resolved (fixed in 5.8.0+ds-2)
OSV
npm Token Leak in npm
osv·2018-07-31
CVE-2016-3956 [HIGH] npm Token Leak in npm
npm Token Leak in npm
Affected versions of the `npm` package include the bearer token of the logged in user in every request made by the CLI, even if the request is not directed towards the user's active registry.
An attacker could create an HTTP server to collect tokens, and by various means including but not limited to install scripts, cause the npm CLI to make a request to that server, which would compromise the user's token.
This compromised token could be used to do anything that the user could do, including publishing new packages.
## Recommendation
1. Update npm with `npm install npm@latest -g`
2. [Revoke your Tokens](https://www.npmjs.com/settings/tokens)
3. Enable [Two-Factor Authentication](https://docs.npmjs.com/getting-started/using-two-factor-authentication)
GHSA
npm Token Leak in npm
ghsa·2018-07-31
CVE-2016-3956 [HIGH] CWE-200 npm Token Leak in npm
npm Token Leak in npm
Affected versions of the `npm` package include the bearer token of the logged in user in every request made by the CLI, even if the request is not directed towards the user's active registry.
An attacker could create an HTTP server to collect tokens, and by various means including but not limited to install scripts, cause the npm CLI to make a request to that server, which would compromise the user's token.
This compromised token could be used to do anything that the user could do, including publishing new packages.
## Recommendation
1. Update npm with `npm install npm@latest -g`
2. [Revoke your Tokens](https://www.npmjs.com/settings/tokens)
3. Enable [Two-Factor Authentication](https://docs.npmjs.com/getting-started/using-two-factor-authentication)
OSV
CVE-2016-3956: The CLI in npm before 2
osv·2016-07-02·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956: The CLI in npm before 2
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files
bugzilla·2016-10-10·CVSS 5.5
CVE-2016-8568 [MEDIUM] CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files
CVE-2016-8568 CVE-2016-8569 libgit2: Invalid memory accesses parsing object files
CVE-2016-8568
* Read out-of-bounds in git_oid_nfmt:
https://github.com/libgit2/libgit2/issues/3936
CVE-2016-8569
* DoS using a null pointer dereference in git_commit_message:
https://github.com/libgit2/libgit2/issues/3937
Proposed patch:
https://github.com/libgit2/libgit2/pull/3956
Discussion:
Created libgit2 tracking bugs for this issue:
Affects: fedora-all [bug 1383212]
Affects: epel-all [bug 1383213]
Bugzilla
CVE-2016-3956 npm: bearer token leak [epel-7]
bugzilla·2016-04-19·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956 npm: bearer token leak [epel-7]
CVE-2016-3956 npm: bearer token leak [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion:
Use the following t
Bugzilla
CVE-2016-3956 npm: bearer token leak to non-registry hosts
bugzilla·2016-04-19·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956 npm: bearer token leak to non-registry hosts
CVE-2016-3956 npm: bearer token leak to non-registry hosts
The primary npm registry has, since late 2014, used HTTP bearer tokens to authenticate requests from the npm command-line interface. Due to a design flaw in the CLI, these bearer tokens were sent with every request made by the CLI for logged-in users, regardless of the destination of the request. They should instead only be included for requests made against the registry or registries used for the current install.
This flaw allows an attacker to set up an HTTP server that could collect authentication information they could use to impersonate the users whose tokens they collected. This impersonation would allow them to do anything the compromised users could do, including publishing new versions of packages.
External references:
Bugzilla
CVE-2016-3956 npm: bearer token leak [epel-6]
bugzilla·2016-04-19·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956 npm: bearer token leak [epel-6]
CVE-2016-3956 npm: bearer token leak [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion:
Use the following t
Bugzilla
CVE-2016-3956 npm: bearer token leak [fedora-all]
bugzilla·2016-04-19·CVSS 7.5
CVE-2016-3956 [HIGH] CVE-2016-3956 npm: bearer token leak [fedora-all]
CVE-2016-3956 npm: bearer token leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one track
http://blog.npmjs.org/post/142036323955/fixing-a-bearer-token-vulnerabilityhttp://www-01.ibm.com/support/docview.wss?uid=swg21980827https://github.com/npm/npm/commit/f67ecad59e99a03e5aad8e93cd1a086ae087cb29https://github.com/npm/npm/commit/fea8cc92cee02c720b58f95f14d315507ccad401https://github.com/npm/npm/issues/8380https://nodejs.org/en/blog/vulnerability/npm-tokens-leak-march-2016/http://blog.npmjs.org/post/142036323955/fixing-a-bearer-token-vulnerabilityhttp://www-01.ibm.com/support/docview.wss?uid=swg21980827https://github.com/npm/npm/commit/f67ecad59e99a03e5aad8e93cd1a086ae087cb29https://github.com/npm/npm/commit/fea8cc92cee02c720b58f95f14d315507ccad401https://github.com/npm/npm/issues/8380https://nodejs.org/en/blog/vulnerability/npm-tokens-leak-march-2016/
2016-07-02
Published