PT-2018-16190 · Npm · Whereis

Chalker

·

Publicado

2018-07-30

·

Atualizado

2019-10-09

·

CVE-2018-3772

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions whereis versions prior to 0.4.1
Description The issue arises from concatenating unsanitized user input in the whereis npm module, allowing an attacker to execute arbitrary commands. It is recommended to use the which npm module instead, as whereis is deprecated.
Recommendations Update to version 0.4.1 or later. As a temporary workaround, consider avoiding the use of the whereis module with untrusted user input until a patch is applied or the module is updated.

Exploit

Correção

Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3772
GHSA-WJR4-2JGW-HMV8

Produtos afetados

Whereis