Description
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/542
Related Vulnerabilities
CVE-2023-29216 Vulnerability in maven package org.apache.linkis:linkis-common
CVE-2014-9634 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2019-10471 Vulnerability in maven package org.jenkins-ci.plugins:libvirt-slave
CVE-2015-0279 Vulnerability in maven package org.richfaces:richfaces-a4j