QID 375936
Date Published: 2021-10-06
QID 375936: Npm Package kill-port-process Command Injection Vulnerability
NPM is a package manager for the JavaScript programming language. It is the default package manager for the JavaScript runtime environment Node.js.
kill-port-process: Cross-platform module to stop one (or more) process(es) running on a port (or a list of ports).
CVE-2019-15609: The kill-port-process package version less than 2.2.0 is vulnerable to a Command Injection vulnerability.
Affected versions:
kill-port-process versions prior to 2.2.0
QID Detection logic:(Authenticated)
It will execute command npm list | grep 'kill-port-process' command to check the system information version
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary command on the target user.
Solution
Customers are advised to update kill-port-process package 2.2.0 or later . Please refer the Vendor advisory link kill-port-process
Vendor References
- npm kill-port-process HomePage -
www.npmjs.com/package/kill-port-process
CVEs related to QID 375936
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| npm kill-port-process HomePage |
|