Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using com.github.codingandcoding:mail-watcher-plugin
altogether.
com.github.codingandcoding:mail-watcher-plugin is a malicious package.
Affected versions of this package are vulnerable to Malicious Package.
Inside the JAR, the backdoored code exists in the send()
method of MailWatcherNotification.class
which, once again, contains a different hardcoded C2 server.