Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-02 05:09:49 +00:00
parent b4cb684cc0
commit 6ea52e3e7c
958 changed files with 1842 additions and 5526 deletions
@@ -3,9 +3,7 @@
"id": "GHSA-2563-83p7-f34p",
"modified": "2021-10-01T14:04:11Z",
"published": "2020-09-02T20:24:41Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in requestt",
"details": "All versions of `requestt` typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.\n\n\n## Recommendation\n\nRemove the package from your dependencies and always ensure package names are typed correctly upon installation.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-277p-xwpp-3jf7",
"modified": "2021-10-01T13:42:09Z",
"published": "2020-09-02T15:49:22Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in rrgod",
"details": "All versions of `rrgod` are considered malicious. The package is malware designed to run arbitrary scripts. When installed, the package downloads an arbitrary file and executes its contents as a pre, post and install scripts.\n\n\n## Recommendation\n\nThis package is not available on the npm Registry anymore. If you happen to find this package in your environment you should consider the system it was installed on compromised and assess if further response (such as rotating all credentials found on the compromised machine) is necessary.\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-2h3x-95c6-885r",
"modified": "2021-09-30T20:01:18Z",
"published": "2020-09-03T17:46:46Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in river-mock",
"details": "All versions of `river-mock` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-2hqf-qqmq-pgpp",
"modified": "2021-10-01T13:30:38Z",
"published": "2020-09-02T15:48:16Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in commander-js",
"details": "All versions of `commander-js` are considered malicious. The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. When installed, the package downloads an arbitrary file and executes its contents as a post-install script.\n\n\n## Recommendation\n\nThis package is not available on the npm Registry anymore. If you happen to find this package in your environment you should consider the system it was installed on compromised and assess if further response (such as rotating all credentials found on the compromised machine) is necessary.\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-2p99-6f47-8x9j",
"modified": "2021-10-01T13:55:37Z",
"published": "2020-09-02T18:38:39Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in asnc",
"details": "All versions of `asnc` typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.\n\n\n## Recommendation\n\nRemove the package from your dependencies and always ensure package names are typed correctly upon installation.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-2r8f-2665-3gxq",
"modified": "2021-09-30T21:54:32Z",
"published": "2020-09-02T21:36:36Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in froever",
"details": "All versions of `froever` contain malicious code as a preinstall script. The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. When installed, the package downloads a file from a remote server, executes it and opened a backdoor.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-2vqq-jgxx-fxjc",
"modified": "2021-09-30T22:07:26Z",
"published": "2020-09-11T21:24:33Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in motiv.scss",
"details": "Version 0.4.20 of `motiv.scss` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-2xw5-3767-qxvm",
"modified": "2021-09-30T22:07:45Z",
"published": "2020-09-11T21:21:20Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in ng-ui-library",
"details": "Version 1.0.987 of `ng-ui-library` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised.",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "Arbitrary JavaScript Execution in typed-function",
"details": "Versions of `typed-function` prior to 0.10.6 are vulnerable to Arbitrary JavaScript Execution. Function names are not properly sanitized and may allow an attacker to execute arbitrary code.\n\n\n## Recommendation\n\nUpgrade to version 0.10.6 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-43vf-2x6g-p2m5",
"modified": "2021-09-30T21:37:54Z",
"published": "2020-09-02T21:33:26Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in browserift",
"details": "Version 16.3.3 of `browserift` contained malicious code as a preinstall script. The package was a backdoor that opened a connection to a remote server and executed incoming commands on both Unix and Windows machines\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-44vf-8ffm-v2qh",
"modified": "2020-08-31T18:34:35Z",
"published": "2020-09-02T15:42:47Z",
"aliases": [
],
"aliases": [],
"summary": "Sensitive Data Exposure in rails-session-decoder",
"details": "All versions of `rails-session-decoder` are missing verification of the Message Authentication Code appended to the cookies. This may lead to decryption of cipher text thus exposing encrypted information.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -36,9 +32,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:34:35Z",
@@ -3,14 +3,10 @@
"id": "GHSA-4627-w373-375v",
"modified": "2020-08-31T18:41:06Z",
"published": "2020-09-11T21:22:24Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in grunt-radical",
"details": "Version 0.0.14 of `grunt-radical` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -42,9 +38,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:41:06Z",
@@ -3,9 +3,7 @@
"id": "GHSA-4964-cjrr-jg97",
"modified": "2021-09-30T21:55:10Z",
"published": "2020-09-02T21:38:43Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in jqeury",
"details": "Version 3.3.1 of `jqeury` contains malicious code as a preinstall script. The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. When installed, the package downloads a file from a remote server, executes it and opened a backdoor.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-4hjg-w3ww-38c6",
"modified": "2021-09-30T20:01:59Z",
"published": "2020-09-03T18:03:49Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in tiar",
"details": "All versions of `tiar` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-4jfq-q299-g4cr",
"modified": "2021-10-01T14:06:36Z",
"published": "2020-09-02T20:28:57Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in reqquest",
"details": "All versions of `reqquest` typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.\n\n\n## Recommendation\n\nRemove the package from your dependencies and always ensure package names are typed correctly upon installation.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-4pmg-jgm5-3jg6",
"modified": "2021-09-30T21:14:54Z",
"published": "2020-09-02T21:16:26Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in erquest",
"details": "All versions of `erquest` typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.\n\n\n## Recommendation\n\nRemove the package from your dependencies and always ensure package names are typed correctly upon installation.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-4q8f-5xxj-946r",
"modified": "2020-08-31T18:41:49Z",
"published": "2020-09-03T02:40:51Z",
"aliases": [
],
"aliases": [],
"summary": "Command Injection in addax",
"details": "Versions of `addax` prior to 1.1.0 are vulnerable to Command Injection. The package does not validate user input on the `presignPath` function which receives input directly from the API endpoint. Exploiting the vulnerability requires authentication. This may allow attackers to run arbitrary commands in the system.\n\n\n## Recommendation\n\nUpgrade to version 1.1.0 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-4wcx-c9c4-89p2",
"modified": "2021-09-30T22:08:42Z",
"published": "2020-09-11T21:23:30Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in react-datepicker-plus",
"details": "Versions 2.4.3 and 2.4.2 of `react-datepicker-plus` contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment and evaluate your application to determine whether or not user data was compromised.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-4x6x-782q-jfc4",
"modified": "2020-08-31T18:41:45Z",
"published": "2020-09-03T02:38:47Z",
"aliases": [
],
"aliases": [],
"summary": "Command Injection in node-wifi",
"details": "Versions of `node-wifi` prior to 2.0.12 are vulnerable to Command Injection. The package fails to sanitize user input, allowing attackers to inject commands through the `ssid` variable and possibly achieving Remote Code Execution on the system.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-4xgp-xrg3-c73w",
"modified": "2021-09-30T22:02:56Z",
"published": "2020-09-11T21:10:29Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in commqnder",
"details": "All versions of `commqnder` contain malicious code . The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. Upon require the package attempts to start a cryptocurrency miner using coin-hive.\n\n\n## Recommendation\n\nRemove the package from your environment and verify whether your system is running the cryptocurrency miner.",
"severity": [

Some files were not shown because too many files have changed in this diff Show More