PT-2020-2801 · Umount+1 · Umount+1

Published

2020-04-02

·

Updated

2022-04-22

·

CVE-2020-7628

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions umount versions 1.1.0 through 1.1.6 install-package versions 1.1.0 through 1.1.6
Description The issue is related to Command Injection. The device argument can be controlled by users without sanitization, allowing the execution of arbitrary commands via the device function. This may enable remote attackers to execute arbitrary code in the system if the device value passed to the function is user-controlled.
Recommendations For umount versions 1.1.0 through 1.1.6, consider using an alternative package until a fix is made available. For install-package versions 1.1.0 through 1.1.6, consider using an alternative package until a fix is made available. As a temporary workaround, consider restricting the use of the device function in the umount module to minimize the risk of exploitation.

Fix

XSS

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02929
CVE-2020-7628
GHSA-6Q48-VJQ2-MWCJ
SNYK-JS-UMOUNT-564265

Affected Products

Package Installer
Umount