Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-37478

Опубликовано: 01 авг. 2023
Источник: debian
EPSS Низкий

Описание

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pnpmitppackage

EPSS

Процентиль: 81%
0.01587
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

CVSS3: 7.5
github
больше 2 лет назад

pnpm incorrectly parses tar archives relative to specification

EPSS

Процентиль: 81%
0.01587
Низкий