Description
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/500
Related Vulnerabilities
CVE-2018-1067 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-32998 Vulnerability in maven package com.rapid7:jenkinsci-appspider-plugin
CVE-2019-1003047 Vulnerability in maven package org.jenkins-ci.plugins:fortify-on-demand-uploader
CVE-2012-0391 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2017-15691 Vulnerability in maven package org.apache.uima:uimaj-adapter-vinci