Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36138

Опубликовано: 07 сент. 2024
Источник: debian
EPSS Низкий

Описание

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsnot-affectedpackage

EPSS

Процентиль: 57%
0.0035
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
nvd
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
github
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 9.8
fstec
12 месяцев назад

Уязвимость программной платформы Node.js, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнять произвольные команды

suse-cvrf
11 месяцев назад

Security update for nodejs18

EPSS

Процентиль: 57%
0.0035
Низкий