sonatype-2024-1970 | Security Details | Sonatype Guide
sonatype-2024-1970
cors-parser - Malicious package at 18 May 2024
Published May 31, 2024
CVSS Score
Critical
10.0
Security Details
Components Impacted
Sonatype Research
sonatype-2024-1970 Security Details
- CVE ID: sonatype-2024-1970
- CVE Description: cors-parser - Malicious package at 18 May 2024
- Published: May 31, 2024
- CVSS Score & Severity: 10.0 Critical
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS Score: 0%
Malware
malware
KEV Status
Not in KEV Catalog: No known exploits
Affected Ecosystems
affected
Source
Sonatype
References
- OSV THIRD_PARTY
- [sonatype.com](/content/blog/cors-parser-npm-package-hides-cross-platform-backdoor-in-png-files "https://www.sonatype.com/blog/cors-parser-npm-package-hides-cross-platform-backdoor-in-png-files"/index.html) THIRD_PARTY