Source |
The Hacker News |
Identifiant |
3368224 |
Date de publication |
2021-09-13 06:48:50 (vue: 2021-09-14 08:07:05) |
Titre |
Critical Bug Reported in NPM Package With Millions of Downloads Weekly |
Texte |
A widely used NPM package called 'Pac-Resolver' for the JavaScript programming language has been remediated with a fix for a high-severity remote code execution vulnerability that could be abused to run malicious code inside Node.js applications whenever HTTP requests are sent.
The flaw, tracked as CVE-2021-23406, has a severity rating of 8.1 on the CVSS vulnerability scoring system and affects |
Notes |
|
Envoyé |
Oui |
Condensat |
2021 23406 abused affects applications are as cve been bug called code could critical cvss downloads execution fix flaw has high http inside javascript language malicious millions node npm pac package programming rating remediated remote reported requests resolver run scoring sent severity system tracked used vulnerability weekly whenever widely |
Tags |
Vulnerability
|
Stories |
|
Move |
|