PT-2018-16190 · Npm · Whereis

Chalker

·

Published

2018-07-30

·

Updated

2019-10-09

·

CVE-2018-3772

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions whereis versions prior to 0.4.1
Description The issue arises from concatenating unsanitized user input in the whereis npm module, allowing an attacker to execute arbitrary commands. It is recommended to use the which npm module instead, as whereis is deprecated.
Recommendations Update to version 0.4.1 or later. As a temporary workaround, consider avoiding the use of the whereis module with untrusted user input until a patch is applied or the module is updated.

Exploit

Fix

Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3772
GHSA-WJR4-2JGW-HMV8

Affected Products

Whereis