PT-2020-21411 · Node.Js · Express
Published
2020-09-02
·
Updated
2020-09-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
experss (affected versions not specified)
Description
The issue concerns a typosquatted package that tracked users who installed it by mistake, thinking it was a similarly named popular package. It uploaded various information to a remote server, including the downloaded package name, the intended package name, the Node version, and whether the process was running with sudo privileges. There is no indication of further compromise.
Recommendations
Remove the experss package from your dependencies and ensure that package names are typed correctly during installation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express