语言:
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
https://github.com/advisories/GHSA-frh7-2f84-v9mw
https://github.com/advisories/GHSA-6jp5-hh4c-8c5h
https://github.com/advisories/GHSA-pxx3-g568-hxr4
https://github.com/advisories/GHSA-5fvm-p68v-5wmh
https://github.com/advisories/GHSA-4x49-vf9v-38px
https://github.com/advisories/GHSA-qrmh-qg46-72pp
https://github.com/advisories/GHSA-286p-vc9p-p5qv
严重性: High
ID: 265444
文件名: npm_supply_chain_attack_08-09-2025.nasl
版本: 1.1
类型: local
系列: Misc.
发布时间: 2025/9/19
最近更新时间: 2025/9/19
支持的传感器: Nessus
风险因素: Low
分数: 3.2
风险因素: High
Base Score: 8.8
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS 分数来源: CVE-2025-59330
CPE: cpe:/a:nodejs:node.js
必需的 KB 项: Host/nodejs/modules/enumerated
补丁发布日期: 2025/9/8
漏洞发布日期: 2025/9/8
CVE: CVE-2025-59140, CVE-2025-59141, CVE-2025-59142, CVE-2025-59143, CVE-2025-59144, CVE-2025-59145, CVE-2025-59162, CVE-2025-59330, CVE-2025-59331