OP Innovate News
1 article
growth-negative
"דרגת סיכון גבוהה": חוקרים ישראליים מצאו חולשה בספריית npm פופולרית
A security vulnerability has been discovered in the npm package manager, specifically in the Kerberos package. The vulnerability allows an attacker to inject malicious code through different versions of the package. The vulnerability affects Windows environments that use DLL files. The Kerberos package loads DLLs into memory based on their name alone, without verifying their full path. This allows an attacker to place a malicious DLL file in the directories the package searches, leading to the execution of the file and potential advanced permissions exploitation. The vulnerability has been rated as high risk. npm has published the findings and urged users to upgrade to version 1.0.0 or above of the Kerberos package.
Customers