Blog | G5 Cyber Security

Critical Bug Reported in NPM Package With Millions of Downloads Weekly

A popular NPM package called Pac-Resolver for Node.js has been fixed for a high-severity remote code execution vulnerability. The flaw, tracked as CVE-2021-23406, has a severity rating of 8.1 on the CVSS vulnerability scoring system. The fix is simple: use a real sandbox instead of the VM built-in module, says Tim Perry. Red Hat, in an independent advisory, said the vulnerable package is shipped with its Advanced Cluster Management for Kubernetes product.”]

Source: https://thehackernews.com/2021/09/critical-bug-reported-in-npm-package.html

Exit mobile version