QID 379429
QID 379429: Postman For MacOS Insufficient Information Vulnerability
An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to Postman 10.23 to address this issue and obtain more information.
Vendor References
- Postman 10.23 -
www.postman.com/release-notes/postman-app/
CVEs related to QID 379429
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Postman 10.23 | MAC OS X |
|