QID 982791
QID 982791: Nodejs (npm) Security Update for lsof (GHSA-whq6-mj2r-mjqc)
All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-whq6-mj2r-mjqc for updates pertaining to this vulnerability.
Vendor References
- GHSA-whq6-mj2r-mjqc -
github.com/advisories/GHSA-whq6-mj2r-mjqc
CVEs related to QID 982791
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-whq6-mj2r-mjqc | lsof |
|