PT-2018-16190 · Npm · Whereis
Chalker
·
Published
2018-07-30
·
Updated
2019-10-09
·
CVE-2018-3772
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
whereis versions prior to 0.4.1
Description
The issue arises from concatenating unsanitized user input in the
whereis npm module, allowing an attacker to execute arbitrary commands. It is recommended to use the which npm module instead, as whereis is deprecated.Recommendations
Update to version 0.4.1 or later.
As a temporary workaround, consider avoiding the use of the
whereis module with untrusted user input until a patch is applied or the module is updated.Exploit
Fix
Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Whereis