Описание
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.10.2 (исключая)
cpe:2.3:a:growl_project:growl:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 91%
0.04412
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
CWE-78
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 8 лет назад
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
CVSS3: 8.1
redhat
около 10 лет назад
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
CVSS3: 9.8
debian
больше 8 лет назад
Growl adds growl notification support to nodejs. Growl before 1.10.2 d ...
CVSS3: 9.8
github
больше 8 лет назад
Growl before 1.10.0 vulnerable to Command Injection
EPSS
Процентиль: 91%
0.04412
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
CWE-78