MAL-2024-4378

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/nuget/bunifu/MAL-2024-4378.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-4378
Published
2024-06-25T13:28:26Z
Modified
2024-10-24T01:01:57Z
Summary
Malicious code in Bunifu (NuGet)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "c0a42e44bfde0836856451afd543fd2cc3ecb23c0f482f98a11acc20c6daee04",
            "import_time": "2024-06-28T02:47:35.87333808Z",
            "versions": [
                "1.0.48",
                "1.0.23",
                "1.0.17",
                "6.3.0",
                "1.0.43",
                "1.0.25",
                "1.0.37",
                "1.0.29",
                "1.0.3",
                "1.0.33",
                "1.0.38",
                "1.0.30",
                "1.0.34",
                "1.0.15",
                "1.0.47",
                "1.0.24",
                "1.0.20",
                "1.0.5",
                "1.0.44",
                "1.0.2",
                "1.0.16",
                "1.0.45",
                "1.0.50",
                "1.0.18",
                "1.0.8",
                "1.0.22",
                "1.0.28",
                "1.0.27",
                "1.0.35",
                "1.0.12",
                "1.0.21",
                "1.0.40",
                "1.0.36",
                "1.0.46",
                "1.0.10",
                "1.0.26",
                "1.0.42",
                "1.0.19",
                "1.0.32",
                "1.0.7",
                "1.0.41",
                "1.0.49",
                "1.0.31",
                "1.0.39",
                "1.0.4",
                "1.0.1",
                "1.0.6",
                "6.3.1",
                "1.0.9",
                "1.0.11",
                "1.0.13",
                "1.0.14"
            ],
            "id": "RLMA-2024-03207",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T13:28:26Z"
        },
        {
            "sha256": "93e88f44740f209f2c531cf2e7c85bceabe9fec608225c9a9e9f1f894b8eb9b8",
            "import_time": "2024-10-24T00:58:35.812874322Z",
            "id": "RLUA-2024-07640",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T13:47:33Z"
        }
    ]
}
References
Credits

Affected packages

NuGet / Bunifu

Package

Affected ranges

Affected versions

1.*

1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.31
1.0.32
1.0.33
1.0.34
1.0.35
1.0.36
1.0.37
1.0.38
1.0.39
1.0.40
1.0.41
1.0.42
1.0.43
1.0.44
1.0.45
1.0.46
1.0.47
1.0.48
1.0.49
1.0.50

6.*

6.3.0
6.3.1