Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2ww-p57h-w5m7

Опубликовано: 07 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

EPSS

Процентиль: 57%
0.0035
Низкий

8.1 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.1
ubuntu
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
nvd
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
debian
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper han ...

CVSS3: 9.8
fstec
12 месяцев назад

Уязвимость программной платформы Node.js, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнять произвольные команды

suse-cvrf
11 месяцев назад

Security update for nodejs18

EPSS

Процентиль: 57%
0.0035
Низкий

8.1 High

CVSS3

Дефекты

CWE-77