Описание
Remote Code Execution in npm-groovy-lint
Versions of npm-groovy-lint prior to 9.1.0 bundle vulnerable versions of the Log4j library which are subject to remote code execution via jndi rendering. As a result npm-groovy-lint prior to 9.1.0 is also vulnerable.
Пакеты
Наименование
npm-groovy-lint
npm
Затронутые версииВерсия исправления
< 9.1.0
9.1.0
Дефекты
CWE-20
Дефекты
CWE-20