GHSA-mh6f-8j2x-4483
Dashboard / Vulnerabilities / GHSA-mh6f-8j2x-4483
GHSA-mh6f-8j2x-4483
Published: 26 Nov 2018Last Modified: 15 Sept 2021
Summary: Critical severity vulnerability that affects event-stream and flatmap-stream
Details: The NPM package `flatmap-stream` is considered malicious. A malicious actor added this package as a dependency to the NPM `event-stream` package in version `3.3.6`. Users of `event-stream` are encouraged to downgrade to the last non-malicious version, `3.3.4`, or upgrade to the latest 4.x version. Users of `flatmap-stream` are encouraged to remove the dependency entirely.
References: https://github.com/dominictarr/event-stream/issues/116, https://github.com/advisories/GHSA-mh6f-8j2x-4483, https://github.com/dominictarr/event-stream
Affected packages
Package
Name: event-stream
Purl: pkg:npm/event-stream
Affected ranges
Type: SEMVER
Events:
Introduced- 3.3.6
Fixed -4.0.0
Affected versions
3.3.6
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
