Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xm2p-chx4-g658

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

Package Managers Configurations Remote Code Execution Vulnerability

Package Managers Configurations Remote Code Execution Vulnerability

EPSS

Процентиль: 72%
0.00733
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
почти 5 лет назад

<p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability affects multiple package managers across multiple languages, including but not limited to: Python/pip, .NET/NuGet, Java/Maven, JavaScript/npm.</p> <p><strong>Attack scenarios</strong></p> <p>An attacker could take advantage of this ecosystem-wide issue to cause harm in a variety of ways. The original attack scenarios were discovered by Alex Birsan and are detailed in their whitepaper, <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies</a>.</p> <ul> <li><p>With basic knowledge of the target ecosystems, an attacker could create an empty shell for a package and inse

msrc
почти 5 лет назад

Package Managers Configurations Remote Code Execution Vulnerability

EPSS

Процентиль: 72%
0.00733
Низкий

8.4 High

CVSS3