Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-36138

Опубликовано: 07 сент. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

РелизСтатусПримечание
devel

not-affected

Only affects Windows
esm-apps/bionic

not-affected

Only affects Windows
esm-apps/focal

not-affected

Only affects Windows
esm-apps/jammy

not-affected

Only affects Windows
esm-apps/noble

not-affected

Only affects Windows
esm-apps/xenial

not-affected

Only affects Windows
esm-infra-legacy/trusty

not-affected

Only affects Windows
focal

not-affected

Only affects Windows
jammy

not-affected

Only affects Windows
mantic

ignored

end of life, was needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 57%
0.0035
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 8.1
debian
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper han ...

CVSS3: 8.1
github
9 месяцев назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS3: 9.8
fstec
12 месяцев назад

Уязвимость программной платформы Node.js, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнять произвольные команды

suse-cvrf
11 месяцев назад

Security update for nodejs18

EPSS

Процентиль: 57%
0.0035
Низкий

8.1 High

CVSS3