QID 982794
QID 982794: Nodejs (npm) Security Update for killport (GHSA-fc42-h7q4-qp8h)
This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command touch success to be executed, leading to the creation of a file called success.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fc42-h7q4-qp8h for updates pertaining to this vulnerability.
Vendor References
- GHSA-fc42-h7q4-qp8h -
github.com/advisories/GHSA-fc42-h7q4-qp8h
CVEs related to QID 982794
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fc42-h7q4-qp8h | killport |
|