Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28xh-wpgr-7fm8

Опубликовано: 20 июн. 2019
Источник: github
Github: Прошло ревью

Описание

Command Injection in open

Versions of open before 6.0.0 are vulnerable to command injection when unsanitized user input is passed in.

The package does come with the following warning in the readme:

The same care should be taken when calling open as if you were calling child_process.exec directly. If it is an executable it will run in a new shell.

Recommendation

open is now the deprecated opn package. Upgrading to the latest version is likely have unwanted effects since it now has a very different API but will prevent this vulnerability.

Пакеты

Наименование

open

npm
Затронутые версииВерсия исправления

< 6.0.0

6.0.0

Дефекты

CWE-77

Дефекты

CWE-77