Логотип exploitDog
bind:CVE-2021-24105
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24105

Количество 3

Количество 3

nvd логотип

CVE-2021-24105

почти 5 лет назад

<p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability affects multiple package managers across multiple languages, including but not limited to: Python/pip, .NET/NuGet, Java/Maven, JavaScript/npm.</p> <p><strong>Attack scenarios</strong></p> <p>An attacker could take advantage of this ecosystem-wide issue to cause harm in a variety of ways. The original attack scenarios were discovered by Alex Birsan and are detailed in their whitepaper, <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies</a>.</p> <ul> <li><p>With basic knowledge of the target ecosystems, an attacker could create an empty shell for a package and inse

CVSS3: 8.4
EPSS: Низкий
msrc логотип

CVE-2021-24105

почти 5 лет назад

Package Managers Configurations Remote Code Execution Vulnerability

EPSS: Низкий
github логотип

GHSA-xm2p-chx4-g658

больше 3 лет назад

Package Managers Configurations Remote Code Execution Vulnerability

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24105

<p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability affects multiple package managers across multiple languages, including but not limited to: Python/pip, .NET/NuGet, Java/Maven, JavaScript/npm.</p> <p><strong>Attack scenarios</strong></p> <p>An attacker could take advantage of this ecosystem-wide issue to cause harm in a variety of ways. The original attack scenarios were discovered by Alex Birsan and are detailed in their whitepaper, <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies</a>.</p> <ul> <li><p>With basic knowledge of the target ecosystems, an attacker could create an empty shell for a package and inse

CVSS3: 8.4
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-24105

Package Managers Configurations Remote Code Execution Vulnerability

1%
Низкий
почти 5 лет назад
github логотип
GHSA-xm2p-chx4-g658

Package Managers Configurations Remote Code Execution Vulnerability

CVSS3: 8.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу