Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cfr-5cjf-32p4

Опубликовано: 16 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 8.3

Описание

lockfile-lint-api Vulnerable to Incorrect Behavior Order

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.

Пакеты

Наименование

lockfile-lint-api

npm
Затронутые версииВерсия исправления

< 5.9.2

5.9.2

EPSS

Процентиль: 16%
0.00051
Низкий

5.5 Medium

CVSS4

8.3 High

CVSS3

Дефекты

CWE-179

Связанные уязвимости

CVSS3: 8.3
nvd
9 месяцев назад

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.

EPSS

Процентиль: 16%
0.00051
Низкий

5.5 Medium

CVSS4

8.3 High

CVSS3

Дефекты

CWE-179