QID 981413
QID 981413: Nodejs (npm) Security Update for nuance-gulp-build-common (GHSA-8695-fr6h-9fq8)
All versions of package nuance-gulp-build-common are vulnerable to Command Injection via the index.js file. PoC: /var a = require("nuance-gulp-build-common") a.run("touch JHU")
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8695-fr6h-9fq8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-8695-fr6h-9fq8 -
github.com/advisories/GHSA-8695-fr6h-9fq8
CVEs related to QID 981413
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8695-fr6h-9fq8 | nuance-gulp-build-common |
|