# sonatype-2024-011414

## request-ip-check - Embedded Malicious Code (Downloads Malicious Binary)

**Published:** Sep 27, 2024  
**CVSS Score:** High - 8.6

## Security Details

### Components Impacted

- Sonatype Research

### CVE ID

- sonatype-2024-011414

### CVE Description

- request-ip-check - Embedded Malicious Code (Downloads Malicious Binary)

### CVSS Score & Severity

- CVSS Score: 8.6 (High)  
- CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

### EPSS Score

- 0%

### Malware

- malware

### KEV Status

- Not in KEV Catalog: No known exploits

### Affected Ecosystems

- affected

### Source

- Sonatype

### References

- [OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2024-9249.json)  
- [sonatype.com](/content/press-releases/next-generation-nexus-intelligence/index.html)
