Affected packages
- @nx/azure-cache
- @nx/gcs-cache
- @nx/powerpack-azure-cache
- @nx/powerpack-gcs-cache
- @nx/powerpack-s3-cache
- @nx/powerpack-shared-fs-cache
- @nx/s3-cache
- @nx/shared-fs-cache
- nx
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/nrwl/nx/security/advisories/GHSA-vp3h-ghgh-jr7g
- https://github.com/nrwl/nx/pull/36116
- https://github.com/nrwl/nx/commit/2b20c2da39d263c32ae05767577589481a309fee
- https://github.com/nrwl/nx/commit/a82807621e4176e37909d2c1afede661b45cc30
- https://github.com/nrwl/nx/commit/ad296578fe980a4aad66f8af0add21f6ddf907d9
- https://github.com/nrwl/nx
Structured record: https://osv.dev/vulnerability/GHSA-vp3h-ghgh-jr7g
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta