Undesired Behavior Affecting moq package, versions [4.20.0,4.20.2)
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DOTNET-MOQ-5830586
- published 9 Aug 2023
- disclosed 8 Aug 2023
- credit DinglDanglBob
How to fix?
Upgrade Moq
to version 4.20.2 or higher.
Overview
Affected versions of this package are vulnerable to Undesired Behavior. It contains a dependency on the SponsorLink
package, which runs an obfuscated closed-source executable at buildtime.
That executable spawns OS processes and performs network requests, including transferring a derivative of personally identifying information (a hash of the email address of the developer from 'git config' output) to remote servers.
NOTE: This change in behavior is in development and this advisory will be updated as new information is available.