Bug bounty hunters awarded $14,500 for ZIP slips

Bug bounty hunters awarded $14,500 for ZIP slips

3 years ago
Anonymous $drS9DEX_Sj

https://www.bleepingcomputer.com/news/security/github-finds-7-code-execution-vulnerabilities-in-tar-and-npm-cli/

GitHub security team has identified several high-severity vulnerabilities in npm packages, "tar" and "@npmcli/arborist," used by npm CLI.

The tar package receives 20 million weekly downloads on average, whereas arborist gets downloaded over 300,000 times every week.