Get a Pentest and security assessment of your IT network.

News

This npm Package Could Have Brought Down Cloudflares Entire CDN and Millions of Websites

Cloudflare has patched a critical vulnerability in its open source content delivery network, CDNJS. The issue threatened the security, integrity, and availability of the wider supply chain. Security researcher RyotaK discovered he could upload a specifically crafted. crafted. package with a Path Traversal or ZIP Slip exploit to achieve remote code execution. The vulnerability works as follows: as soon as CDN.JS fetches a new release from. npm its automated bots would unpack (unzip) the new library. The author of this newly published library could choose to release subsequent versions of the library on the. npm registry. And these would automatically be fetched by CDN.”]

Source: https://blog.sonatype.com/this-npm-package-could-have-brought-down-cloudflares-entire-cdn-and-millions-of-websites

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months