
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical security vulnerability was identified in the npm package 'geoheat' version 1.3.2, discovered and disclosed on August 31, 2020. The vulnerability was published to the GitHub Advisory Database on September 11, 2020, and was last updated on July 27, 2023. This security issue affects specifically version 1.3.2 of the geoheat package (GitHub Advisory).
The vulnerability involves malicious code embedded in version 1.3.2 of the geoheat package. When executed in a browser environment, the malicious code specifically targets form fields containing sensitive information, including passwords, CVC numbers, and credit card numbers. The compromised data is then exfiltrated to an external endpoint at js-metrics.com/minjs.php?pl= (GitHub Advisory).
The vulnerability poses a severe risk to user privacy and financial security as it specifically targets sensitive payment information including credit card numbers, CVC codes, and passwords from web forms. Any application incorporating the compromised version of the package could potentially expose users' financial data to unauthorized collection (GitHub Advisory).
The malicious code is automatically executed when the compromised package version is implemented in a browser environment, making it highly exploitable with no additional user interaction required. The code actively harvests sensitive data from form fields and transmits it to an external server (GitHub Advisory).
Users are strongly advised to remove version 1.3.2 of the geoheat package from their environment immediately. It is recommended to conduct a thorough evaluation of applications to determine if any user data has been compromised. As a temporary solution, users can downgrade to version 1.3.1 of the package. No patches are available as this is a malicious package rather than a vulnerability that can be fixed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."