Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36138

Опубликовано: 07 сент. 2024
Источник: debian
EPSS Низкий

Описание

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsnot-affectedpackage

EPSS

Процентиль: 63%
0.00445
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
11 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
nvd
11 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
github
11 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость программной платформы Node.js, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнять произвольные команды

suse-cvrf
около 1 года назад

Security update for nodejs18

EPSS

Процентиль: 63%
0.00445
Низкий