CVE-2018-21268
Summary
| CVE | CVE-2018-21268 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-25 17:15:00 UTC |
| Updated | 2023-11-07 02:56:00 UTC |
| Description | The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Traceroute Project | Traceroute | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Overview | MISC | www.npmjs.com | Third Party Advisory |
| Shell Command Injection Through Traceroute NPM Package | by OP Innovate | Medium | medium.com | ||
| Page not found – OP Innovate | MISC | www.op-c.net | Exploit, Third Party Advisory |
| OP Innovate on LinkedIn: Shell Command Injection Through Traceroute NPM Package | MISC | www.linkedin.com | Third Party Advisory |
| Shell Command Injection Through Traceroute NPM Package | by OP Innovate | Medium | MISC | medium.com | Exploit, Third Party Advisory |
| Shell Command Injection in traceroute | Snyk | MISC | snyk.io | Exploit, Third Party Advisory |
| traceroute - npm | MISC | www.npmjs.com | Product, Third Party Advisory |
| conversion to spawn and stream · jaw187/node-traceroute@b99ee02 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Tags · jaw187/node-traceroute · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.