Описание
compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.5 (исключая)
cpe:2.3:a:compile-sass_project:compile-sass:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00432
Низкий
8.2 High
CVSS3
8.5 High
CVSS2
Дефекты
CWE-78
Связанные уязвимости
EPSS
Процентиль: 62%
0.00432
Низкий
8.2 High
CVSS3
8.5 High
CVSS2
Дефекты
CWE-78