Описание
Command injection in samba-client
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-27185
- https://github.com/eflexsystems/node-samba-client/commit/5bc3bbad9b8d02243bc861a11ec73f788fbb1235
- https://advisory.checkmarx.net/advisory/CX-2021-4302
- https://github.com/eflexsystems/node-samba-client/releases/tag/4.0.0
- https://security.netapp.com/advisory/ntap-20210319-0002
- https://www.npmjs.com/package/samba-client
Пакеты
Наименование
samba-client
npm
Затронутые версииВерсия исправления
< 4.0.0
4.0.0
Связанные уязвимости
CVSS3: 9.8
nvd
почти 5 лет назад
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.