QID 981910
QID 981910: Nodejs (npm) Security Update for pulverizr (GHSA-fmf5-j5j9-99pp)
pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fmf5-j5j9-99pp for updates pertaining to this vulnerability.
Vendor References
- GHSA-fmf5-j5j9-99pp -
github.com/advisories/GHSA-fmf5-j5j9-99pp
CVEs related to QID 981910
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fmf5-j5j9-99pp | pulverizr |
|