Executive brief
The pem npm package, a Node.js library for working with X.509 certificates and keys, creates temporary files containing PKCS12 encryption passwords in the system temp directory with world-readable permissions. An attacker with local file access can read these unencrypted password files, gaining unauthorized access to certificate data and private keys. This affects any application using pem to handle encrypted certificates.
Technical details
The vulnerability is an information disclosure flaw (CWE-200) in the readPkcs12 function of versions prior to 1.13.2. The function generates a temporary file with a 20-character hexadecimal name containing the PKCS12 decryption password, then passes it to OpenSSL for certificate processing. The file is created with globally readable permissions and is never deleted, leaving the plaintext password accessible to any user with access to the filesystem (typically all local users). An attacker with local access to the system can enumerate temporary files and read the password, enabling unauthorized decryption of PKCS12 containers. The fix (committed October 2018, released as 1.13.2) removes this insecure temporary file approach. No network access is required; exploitation requires local file system read access.
Affected products
- npm pem before 1.13.2
Timeline
- 2019-06-04: disclosed
- 2018-10-26: patched: Fix merged; version 1.13.2 or later contains the patch