QID 981907
QID 981907: Nodejs (npm) Security Update for docker-compose-remote-api (GHSA-q6pj-jh94-5fpr)
docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q6pj-jh94-5fpr for updates pertaining to this vulnerability.
Vendor References
- GHSA-q6pj-jh94-5fpr -
github.com/advisories/GHSA-q6pj-jh94-5fpr
CVEs related to QID 981907
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q6pj-jh94-5fpr | docker-compose-remote-api |
|