Spectra Assure
Community
Docs
failRisk: Vulnerabilities
Scanned: 10 days ago

Gist Extension

Artifact:
latest
Top 10k
Create, open and edit Gists
License: unknown
Published: over 8 years ago

Publisher: dbankier



SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
No sensitive information found

Security

Vulnerabilities
13 severe vulnerabilities exploited
Hardening
No application hardening issues

Threats

Tampering
No evidence of software tampering
Malware
No evidence of malware inclusion

Popularity

22.47k
Total Installs
Contributor
Declared Dependencies
0
Dependents

Top issues

Problem

Software composition analysis has identified a component with one or more known severe vulnerabilities. Available threat intelligence telemetry has confirmed that the reported high or critical severity vulnerabilities are actively being exploited by malicious actors.

Prevalence in Visual Studio Code community

71 packages
found in
Top 100
568 packages
found in
Top 1k
3198 packages
found in
Top 10k
16595 packages
in community

Next steps

We strongly advise updating the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as critical severity.

Prevalence in Visual Studio Code community

64 packages
found in
Top 100
445 packages
found in
Top 1k
2064 packages
found in
Top 10k
9214 packages
in community

Next steps

Perform impact analysis for the reported CVEs.
We strongly advise updating the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as high severity.

Prevalence in Visual Studio Code community

72 packages
found in
Top 100
583 packages
found in
Top 1k
3344 packages
found in
Top 10k
17282 packages
in community

Next steps

Perform impact analysis for the reported CVEs.
Update the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Uniform Resource Locators (URLs) are structured addresses that point to locations and assets on the internet. URLs allow software developers to build complex applications that exchange data with servers that can be hosted in multiple geographical regions. URLs can commonly be found embedded in documentation, configuration files, source code and compiled binaries. Bitcoin (BTC) is a digital currency that uses peer-to-peer technology to facilitate instant payments on the web. Bitcoin exchanges allow their customers to trade cryptocurrencies or digital currencies for other assets, such as conventional fiat money or other digital currencies. Financially motivated actors often include references to cryptocurrency exchanges in their code. Ransomware victims are instructed to visit Bitcoin exchanges to acquire the digital currency. Bitcoin is the most common payment method accepted by attackers in exchange for decrypting the user-generated data that is held for ransom. While presence of Bitcoin exchange service references does not imply malicious intent, all of its uses in a software package should be documented and approved. Only select applications should consider keeping track of Bitcoin exchange websites.

Prevalence in Visual Studio Code community

11 packages
found in
Top 100
84 packages
found in
Top 1k
280 packages
found in
Top 10k
976 packages
in community

Next steps

Investigate reported detections.
If the software should not include these network references, investigate your build and release environment for software supply chain compromise.
You should delay the software release until the investigation is completed, or until the issue is risk accepted.
Consider removing all references to flagged network locations.

Problem

Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as medium severity.

Prevalence in Visual Studio Code community

70 packages
found in
Top 100
531 packages
found in
Top 1k
3115 packages
found in
Top 10k
16606 packages
in community

Next steps

Perform impact analysis for the reported CVEs.
Update the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Top behaviors

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
65 packages
found in
Top 100
535 packages
found in
Top 1k
2853 packages
found in
Top 10k
14133 packages
in community

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
15 packages
found in
Top 100
110 packages
found in
Top 1k
397 packages
found in
Top 10k
2369 packages
in community

Prevalence in Visual Studio Code community

Behavior commonly used by malicious software (Important)
Behavior often found in this community (Common)
11 packages
found in
Top 100
84 packages
found in
Top 1k
280 packages
found in
Top 10k
976 packages
in community

Prevalence in Visual Studio Code community

Behavior often found in this community (Common)
85 packages
found in
Top 100
673 packages
found in
Top 1k
4329 packages
found in
Top 10k
28768 packages
in community

Prevalence in Visual Studio Code community

Behavior commonly used by malicious software (Important)
Behavior often found in this community (Common)
10 packages
found in
Top 100
73 packages
found in
Top 1k
201 packages
found in
Top 10k
739 packages
in community

Top vulnerabilities

Vulnerability Exploitation Lifecycle
(29 Active Vulnerabilities)
9 (8 Fixable)
CVE-2018-1000620c
CVE-2020-36604h
CVE-2017-15010h
20 (19 Fixable)
CVE-2018-16492c
CVE-2021-23807c
CVE-2021-3918c
None
None
Exploits Unknown
Exploits Exist
Exploited by Malware
Patching Mandated