Описание
OS Command Injection in closure-compiler-stream
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument options of the exports function in index.js can be controlled by users without any sanitization.
Пакеты
Наименование
closure-compiler-stream
npm
Затронутые версииВерсия исправления
<= 0.1.15
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
почти 6 лет назад
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.