Node.js fk-react-lottie-player execution |
NAME
Node.js fk-react-lottie-player execution
- Platforms Affected:
Node.js fk-react-lottie-player - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Gain Access
DESCRIPTION
Node.js fk-react-lottie-player could allow a remote attacker to execute arbitrary code on the system, caused by the containment of malicious package. An attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of June 27, 2022.
- Reference Link:
https://security.snyk.io/vuln/SNYK-JS-FKREACTLOTTIEPLAYER-2934702 - Reference Link:
https://www.npmjs.com/package/fk-react-lottie-player
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.