QID 379459
QID 379459: Postman For MacOS Insufficient Information Vulnerability
An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."
Affected Version
Postman version 10.22 and before
QID Detection Logic (Authenticated)
This qid checks for vulnerable version of Postman
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to link to address this issue and obtain more information.
Vendor References
CVEs related to QID 379459
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-23738 | MacOs |
|