Node.js atatresmedia/intranet-svg code execution |
NAME
Node.js atatresmedia/intranet-svg code execution
- Platforms Affected:
Node.js @atresmedia/intranet-svg - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Gain Access
DESCRIPTION
Node.js atatresmedia/intranet-svg could allow a remote attacker to execute arbitrary code on the system, caused by the containment of malicious package. An attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of June 27, 2022.
- Reference Link:
https://security.snyk.io/vuln/SNYK-JS-ATRESMEDIAINTRANETSVG-2934703 - Reference Link:
https://www.npmjs.com/package/@atresmedia/intranet-svg
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.