Intel

AIKIDO-2024-10386

ether/simplemap is vulnerable to Malicious Code

Malicious CodeCVE-2024-38526 Published Oct 29, 2024

100

Critical Risk

This Affects:

phpether/simplemap
1.0.0 - 3.9.4
Fixed in 3.9.5
4.0.0 - 4.0.7
Fixed in 4.0.8
5.0.0 - 5.0.0
Fixed in 5.0.1
Are you affected? Scan for Free

TL;DR

The ether/simplemap package is vulnerable due to its use of polyfill[.]io, which has been compromised by attackers and serves malicious code.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ether/simplemap is vulnerable to Malicious Code in versions 1.0.0 - 3.9.4, 4.0.0 - 4.0.7 and 5.0.0 - 5.0.0.

How to fix this

Upgrade the ether/simplemap library to a patch version.