Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pp57-mqmh-44h7

Опубликовано: 06 сент. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Command Injection in macaddress

All versions of macaddress are vulnerable to command injection. For this vulnerability to be exploited an attacker needs to control the iface argument to the one method.

Recommendation

Update to version 0.2.9 or later.

Пакеты

Наименование

macaddress

npm
Затронутые версииВерсия исправления

< 0.2.9

0.2.9

EPSS

Процентиль: 93%
0.11295
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
redhat
больше 7 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
nvd
больше 7 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
debian
больше 7 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrar ...

EPSS

Процентиль: 93%
0.11295
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78