QID 980944
QID 980944: Nodejs (npm) Security Update for dns-sync (GHSA-q5pq-pgrv-fh89)
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q5pq-pgrv-fh89 for updates pertaining to this vulnerability.
Vendor References
- GHSA-q5pq-pgrv-fh89 -
github.com/advisories/GHSA-q5pq-pgrv-fh89
CVEs related to QID 980944
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q5pq-pgrv-fh89 | dns-sync |
|