AppThreat / AppThreat/vulnerability-db

npm:phpmyadmin is both malicious and legitimate

Open
#212 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
151
Forks
23
Avg merge
22m
Merged PRs (30d)
7

Description

As per OSV, all [versions](https://osv.dev/vulnerability/MAL-2022-5327) of npm:phpmyadmin are malicious.

However, this npm [package](https://github.com/phpmyadmin/phpmyadmin/blob/39670a0908bc9212a13e37e70b428bfe35867706/package.json#L2) is quite legitimate, although the project never publishes the same on npm.

Currently, when constructing or searching for a PURL, we don't really consider the `published` status of a package. Let's use this ticket to track some ideas.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.