Miggo Logo

CVE-2017-16066: opencv.js is malware

7.5

CVSS Score
3.0

Basic Information

EPSS Score
0.50347%
Published
8/29/2018
Updated
9/7/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
opencv.jsnpm<= 1.2.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The advisory describes opencv.js as a malicious package designed to hijack environment variables, but no specific code samples or function-level details are provided in the available vulnerability reports. The CWE-506 classification indicates embedded malicious code, which typically involves unauthorized environment variable access (e.g., via Node.js's process.env), but without access to the unpublished package's source code, commit diffs, or patch details, we cannot identify specific functions with high confidence. The lack of GitHub patch information and commit diff data further limits the ability to pinpoint vulnerable functions.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

op*n*v.js w*s * m*li*ious mo*ul* pu*lis*** wit* t** int*nt to *ij**k *nvironm*nt v*ri**l*s. It **s ***n unpu*lis*** *y npm.

Reasoning

T** **visory **s*ri**s op*n*v.js *s * m*li*ious p**k*** **si*n** to *ij**k *nvironm*nt v*ri**l*s, *ut no sp**i*i* *o** s*mpl*s or *un*tion-l*v*l **t*ils *r* provi*** in t** *v*il**l* vuln*r**ility r*ports. T** *W*-*** *l*ssi*i**tion in*i**t*s *m*****