PT-2017-10916 · Soyuka · Pidusage

Published

2017-11-17

·

Updated

2022-05-13

·

CVE-2017-1000220

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions soyuka/pidusage versions 1.1.4 and earlier
Description The issue allows for command injection in the module, resulting in arbitrary command execution. Affected versions of pidusage pass unsanitized input to child process.exec(), leading to arbitrary code execution in the ps method. This affects Darwin, SunOS, FreeBSD, and AIX, while Windows and Linux are not vulnerable.
Recommendations Update to version 1.1.5 or later. As a temporary workaround, consider avoiding the use of the ps method in the pidusage module until the issue is resolved. Restrict access to the child process.exec() function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000220
GHSA-H2P3-H48H-9JJ7

Affected Products

Pidusage