Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r6j-v8pm-fqw3

Опубликовано: 06 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Code injection in fsevents

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary.

Пакеты

Наименование

fsevents

npm
Затронутые версииВерсия исправления

<= 1.2.10

1.2.11

EPSS

Процентиль: 62%
0.00426
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

CVSS3: 9.8
nvd
больше 2 лет назад

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

EPSS

Процентиль: 62%
0.00426
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94