21.2.15
8 days ago
8 days ago
Known vulnerabilities in the @infoserver/gov-shared-ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@infoserver/gov-shared-ui is a malicious package. that is designed to exfiltrate data and spawn a reverse shell on any system that installs it. An attacker could open ports to the target machines, forcing communication and enabling a complete takeover of the target machine. How to fix Embedded Malicious Code? Avoid using all malicious instances of the | * |