Skip to content

Conversation

@github-actions
Copy link

Vulnerabilities associated with fsevents/1.2.9

BDSA-2023-1218 (HIGH): fsevents npm package is vulnerable to hijacking due to malicious code run during installation via a hijacked URL in the install configuration. This would allow the current owner of the URL to run code of their choosing on each installation of the package.

Note: Originally, the credentials to the S3 bucket of the affected URL were lost. It was demonstrated by a security researcher that the bucket became available to register once again, and it was taken over by the researcher to demonstrate possible impact of this vulnerability. At this time, AWS has taken possession of the S3 bucket and currently blocks all access, neutralizing any threat. Should this bucket become available to use in the future, affected versions of fsevents will once again become vulnerable. This occurred in August 2023, when the bucket was briefly reinstated in error.

Click Here To See More Details On Server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant