Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chh2-rvhg-wqwr

Опубликовано: 03 сент. 2020
Источник: github
Github: Прошло ревью

Описание

Malicious Package in json-serializer

Version 2.0.10 of json-serializer contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=

Recommendation

Remove the package from your environment and evaluate your application to determine whether or not user data was compromised.

Пакеты

Наименование

json-serializer

npm
Затронутые версииВерсия исправления

= 2.0.10

2.0.11