CVE-2022-21704

MEDIUM

Log4js < 6.4.0 - Incorrect Default Permissions

Title source: rule
STIX 2.1

Description

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (3)
debian/debian_linux 10.0
log4js_project/log4js < 6.4.0
npm/log4js 0 - 6.4.0npm
Published Jan 19, 2022
Tracked Since Feb 18, 2026