QID 982763
QID 982763: Nodejs (npm) Security Update for config-shield (GHSA-w8h4-vw8f-rvvj)
scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w8h4-vw8f-rvvj for updates pertaining to this vulnerability.
Vendor References
- GHSA-w8h4-vw8f-rvvj -
github.com/advisories/GHSA-w8h4-vw8f-rvvj
CVEs related to QID 982763
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w8h4-vw8f-rvvj | config-shield |
|