Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-13797

Опубликовано: 10 июл. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:node-macaddress_project:node-macaddress:*:*:*:*:*:node.js:*:*
Версия до 0.2.9 (исключая)

EPSS

Процентиль: 93%
0.06664
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
redhat
около 8 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

CVSS3: 9.8
debian
около 8 лет назад

The macaddress module before 0.2.9 for Node.js is prone to an arbitrar ...

CVSS3: 9.8
github
почти 8 лет назад

Command Injection in macaddress

EPSS

Процентиль: 93%
0.06664
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-78