QID 982922
QID 982922: Nodejs (npm) Security Update for react-dev-utils (GHSA-5q6m-3h65-w53x)
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this function is manually invoked with user-provided values (ie: by custom code) is there the potential for command injection. If you're consuming it from react-scripts then this issue does not affect you.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5q6m-3h65-w53x for updates pertaining to this vulnerability.
Vendor References
- GHSA-5q6m-3h65-w53x -
github.com/advisories/GHSA-5q6m-3h65-w53x
CVEs related to QID 982922
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5q6m-3h65-w53x | react-dev-utils |
|