Data Exfiltration Vulnerability in Coffeescript Module by Node Security
CVE-2017-16202

7.5HIGH

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
7 June 2018

What is CVE-2017-16202?

The Coffeescript module has a critical vulnerability that allows the exfiltration of sensitive user data, including private SSH keys and bash history, to a third-party server during installation. This can lead to severe privacy breaches and unauthorized access, making it crucial for users to be aware of this risk. Ensure that your usage of the Coffeescript module is secured and up-to-date to mitigate potential exposure.

Affected Version(s)

coffeescript node module 1.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.