Data Exfiltration Vulnerability in coffe-script Module
CVE-2017-16203

7.5HIGH

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
26 April 2018

What is CVE-2017-16203?

The coffe-script module has a vulnerability that enables the exfiltration of sensitive user data, including private SSH keys and bash history, to a third-party server during installation. This poses a significant risk to user privacy and data security, as malicious actors could exploit this vulnerability to gain unauthorized access to sensitive information.

Affected Version(s)

coffeescript node module 1.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.