QID 982628
QID 982628: Nodejs (npm) Security Update for geojson2kml (GHSA-w83x-fp72-p9qc)
All versions up to and including version 0.1.1 of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w83x-fp72-p9qc for updates pertaining to this vulnerability.
Vendor References
- GHSA-w83x-fp72-p9qc -
github.com/advisories/GHSA-w83x-fp72-p9qc
CVEs related to QID 982628
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w83x-fp72-p9qc | geojson2kml |
|