QID 982780
QID 982780: Nodejs (npm) Security Update for port-killer (GHSA-2548-q746-x5x6)
This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command touch success to be executed, leading to the creation of a file called success.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2548-q746-x5x6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2548-q746-x5x6 -
github.com/advisories/GHSA-2548-q746-x5x6
CVEs related to QID 982780
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2548-q746-x5x6 | port-killer |
|