Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10541

Опубликовано: 31 мая 2018
Источник: debian
EPSS Низкий

Описание

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-shell-quotenot-affectedpackage

Примечания

  • https://nodesecurity.io/advisories/117

  • nodejs not covered by security support

EPSS

Процентиль: 60%
0.00397
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.

CVSS3: 8.4
redhat
больше 9 лет назад

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.

CVSS3: 9.8
nvd
больше 7 лет назад

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.

CVSS3: 9.8
github
почти 7 лет назад

Potential Command Injection in shell-quote

EPSS

Процентиль: 60%
0.00397
Низкий