PT-2018-16190 · Npm · Whereis
Chalker
·
Publicado
2018-07-30
·
Atualizado
2019-10-09
·
CVE-2018-3772
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
whereis versions prior to 0.4.1
Description
The issue arises from concatenating unsanitized user input in the
whereis npm module, allowing an attacker to execute arbitrary commands. It is recommended to use the which npm module instead, as whereis is deprecated.Recommendations
Update to version 0.4.1 or later.
As a temporary workaround, consider avoiding the use of the
whereis module with untrusted user input until a patch is applied or the module is updated.Exploit
Correção
Command Injection
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Whereis