Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35847
HistoryJun 03, 2022 - 5:40 a.m.

Supply Chain Attack

2022-06-0305:40:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
npm
supply chain
attack
vulnerability
software
verification
workspace path

EPSS

0.002

Percentile

58.3%

npm is vulnerable to supply chain attack. The vulnerability exists due to the lack of verification root-level workspace path.