Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvh2-82c7-ppfg

Опубликовано: 30 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

network Arbitrary Command Injection vulnerability

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for an attacker to execute arbitrary commands on the operating system that this package is being run on.

Пакеты

Наименование

network

npm
Затронутые версииВерсия исправления

< 0.7.0

0.7.0

EPSS

Процентиль: 82%
0.01689
Низкий

7.3 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.3
nvd
около 2 лет назад

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.

CVSS3: 7.3
fstec
около 2 лет назад

Уязвимость функции child_process exec кроссплатформенной сетевой утилиты Node.js Network, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 82%
0.01689
Низкий

7.3 High

CVSS3

Дефекты

CWE-77