å æ¥ã¢ãã¦ã³ã¹ãããèå¼±æ§ã¨ãã®å¨è¾ºã«ã¤ãã¦ãã¨ãã¨ããªãã The npm Blog â Package install scripts vulnerability Vulnerability Note VU#319816 èå¼±æ§ã®æ¦è¦ VU#319816 ã«ããã°ãä»ååé¡ã«ãªã£ã¦ããã®ã¯npmã®ä»¥ä¸ã®æ§è³ªãå©ç¨ããã¨npmããã±ã¼ã¸ã§ã¯ã¼ã ï¼èªå·±å¢æ®åã®ãããã«ã¦ã§ã¢ï¼ãä½ããã¨ãããã®ã ä¾åããã±ã¼ã¸ã®ãã¼ã¸ã§ã³ãããã¯ãããsemverã«ããç¯å²æå®ãããã¨ãå¤ã CLIã§ä¸åº¦npmã¸loginããã¨ãæ示çã«npm logoutããã¾ã§èªè¨¼ãæ°¸ç¶åããã npm registry ãä¸å¤®é権åãµã¼ãã¼ã§ãã å ·ä½çãªææ³ã¨ãã¦ãChris Contoliniã PoC ã¨ã㦠pizza-party ã¨ãããªãã¸ããªãå ¬éãã¦ãã*1ã以ä¸ã®ããã«åä½ããã ã¯ã¼ã ãä»è¾¼ã¾ã
{{#tags}}- {{label}}
{{/tags}}