PT-2018-6155 · Npm · Pandora-Doomsday

Publicado

2018-06-07

·

Atualizado

2020-09-01

·

CVE-2017-16127

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: pandora-doomsday (affected versions not specified)
Description: The issue concerns a malicious package named pandora-doomsday that infects other modules by adding itself to their package.json files and attempting to publish the compromised packages. This package has been removed from the npm registry. Any computer with this package installed should be considered fully compromised, and all secrets and keys stored on it should be rotated immediately from a different computer.
Recommendations: To address the issue, remove the pandora-doomsday package, but be aware that this may not remove all malicious software resulting from its installation, as full control of the computer may have been given to an outside entity. Consider rotating all secrets and keys stored on the compromised computer immediately from a different computer.

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16127
GHSA-428F-MH7W-6W2X

Produtos afetados

Pandora-Doomsday