Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r5x-qjqc-p579

Опубликовано: 01 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Tracking Module in botbait

The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem.

botbait is known to record and track user information.

The module tracks the following information.

  • Source IP
  • process.versions
  • process.platform
  • How the module was invoked (test, require, pre-install)

Recommendation

This package has no functional value, and should be removed from your environment if discovered.

Пакеты

Наименование

botbait

npm
Затронутые версииВерсия исправления

>= 0.0.0

Отсутствует

EPSS

Процентиль: 46%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user information. The module tracks the following information. Source IP process.versions process.platform How the module was invoked (test, require, pre-install)

EPSS

Процентиль: 46%
0.00232
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200