QID 982778
QID 982778: Nodejs (npm) Security Update for serial-number (GHSA-3fw4-4h3m-892h)
serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function without any validation.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3fw4-4h3m-892h for updates pertaining to this vulnerability.
Vendor References
- GHSA-3fw4-4h3m-892h -
github.com/advisories/GHSA-3fw4-4h3m-892h
CVEs related to QID 982778
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3fw4-4h3m-892h | serial-number |
|