Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xhv-mpjw-422f

Опубликовано: 03 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Command injection in google-it

Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE.

Пакеты

Наименование

google-it

npm
Затронутые версииВерсия исправления

<= 1.6.2

Отсутствует

EPSS

Процентиль: 70%
0.00649
Низкий

8.1 High

CVSS3

Дефекты

CWE-74
CWE-78

Связанные уязвимости

CVSS3: 8.1
nvd
больше 3 лет назад

Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE.

EPSS

Процентиль: 70%
0.00649
Низкий

8.1 High

CVSS3

Дефекты

CWE-74
CWE-78