CVE Vulnerabilities

CVE-2017-16075

Embedded Malicious Code

Published: Jun 07, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Weakness

The product contains code that appears to be malicious in nature.

Affected Software

NameVendorStart VersionEnd Version
Http-proxy.jsHttp-proxy.js_project**

Potential Mitigations

References