QID 981861
QID 981861: Nodejs (npm) Security Update for mock2easy (GHSA-g4xj-wcq6-qwx5)
This affects all versions up to and including version 0.0.24 of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { return res.json(500, error); } res.json(JSON.parse(stdout)); }, ', _data.interfaceUrl, query, _data.cookie,_data.interfaceType);
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g4xj-wcq6-qwx5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-g4xj-wcq6-qwx5 -
github.com/advisories/GHSA-g4xj-wcq6-qwx5
CVEs related to QID 981861
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g4xj-wcq6-qwx5 | mock2easy |
|