QID 982787
QID 982787: Nodejs (npm) Security Update for eslint-fixer (GHSA-45w5-pvr8-4rh5)
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-45w5-pvr8-4rh5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-45w5-pvr8-4rh5 -
github.com/advisories/GHSA-45w5-pvr8-4rh5
CVEs related to QID 982787
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-45w5-pvr8-4rh5 | eslint-fixer |
|