AppThreat / AppThreat/vulnerability-db
npm:phpmyadmin is both malicious and legitimate
Open
- Dominant language
- Python
- Stars
- 151
- Forks
- 23
- Avg merge
- 22m
- Merged PRs (30d)
- 7
Description
As per OSV, all [versions](https://osv.dev/vulnerability/MAL-2022-5327) of npm:phpmyadmin are malicious.
However, this npm [package](https://github.com/phpmyadmin/phpmyadmin/blob/39670a0908bc9212a13e37e70b428bfe35867706/package.json#L2) is quite legitimate, although the project never publishes the same on npm.
Currently, when constructing or searching for a PURL, we don't really consider the `published` status of a package. Let's use this ticket to track some ideas.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.