Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-13797

Опубликовано: 10 июл. 2018
Источник: debian
EPSS Низкий

Описание

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-macaddressfixed0.2.9-1package

Примечания

  • https://github.com/scravy/node-macaddress/pull/20

  • nodejs not covered by security support

EPSS

Процентиль: 93%
0.06664
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
redhat
около 8 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
nvd
около 8 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
github
почти 8 лет назад

Command Injection in macaddress

EPSS

Процентиль: 93%
0.06664
Низкий