GHSA-hxxf-q3w9-4xgw

Suggest an improvement
Source
https://github.com/advisories/GHSA-hxxf-q3w9-4xgw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-hxxf-q3w9-4xgw/GHSA-hxxf-q3w9-4xgw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hxxf-q3w9-4xgw
Published
2018-07-12T19:52:02Z
Modified
2021-09-14T17:35:41Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Malicious Package in eslint-scope
Details

Version 3.7.2 of eslint-scope was published without authorization and was found to contain malicious code. This code would read the users .npmrc file and send any found authentication tokens to 2 remote servers.

Recommendation

The best course of action if you found this package installed in your environment is to revoke all your npm tokens. You can find instructions on how to do that here. https://docs.npmjs.com/getting-started/working_with_tokens#how-to-revoke-tokens

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:41:33Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / eslint-scope

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.7.2
Fixed
3.7.3

Affected versions

3.*
3.7.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-hxxf-q3w9-4xgw/GHSA-hxxf-q3w9-4xgw.json"

npm / eslint-config-eslint

Package

Name
eslint-config-eslint
View open source insights on deps.dev
Purl
pkg:npm/eslint-config-eslint

Affected ranges

Type
SEMVER
Events
Introduced
5.0.2
Fixed
6.0.0

Affected versions

5.*
5.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-hxxf-q3w9-4xgw/GHSA-hxxf-q3w9-4xgw.json"