QID 981932
QID 981932: Nodejs (npm) Security Update for closure-compiler-stream (GHSA-m647-5wf9-3jp3)
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m647-5wf9-3jp3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-m647-5wf9-3jp3 -
github.com/advisories/GHSA-m647-5wf9-3jp3
CVEs related to QID 981932
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m647-5wf9-3jp3 | closure-compiler-stream |
|