PT-2020-12537 · Node.Js · Node-Dns-Sync

Erik Krogh Kristensen

+1

·

Published

2020-05-28

·

Updated

2021-11-03

·

CVE-2020-11079

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions node-dns-sync versions 0.2.0 and earlier
Description The issue allows execution of arbitrary commands, potentially leading to remote code execution if a client of the library calls the vulnerable method with untrusted input.
Recommendations For versions 0.2.0 and earlier, update to version 0.2.1 to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable method to trusted input only until the update is applied.

Fix

Command Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11079
GHSA-WH69-WC6Q-7888

Affected Products

Node-Dns-Sync