QID 983067
QID 983067: Nodejs (npm) Security Update for larvitbase-api (GHSA-xf27-jqwv-gf3r)
Versions of `larvitbase-api` prior to 0.5.4 are vulnerable to an Unintended Require. The package exposes an API endpoint and passes a GET parameter unsanitized to an `require()` call. This allows attackers to execute any `.js` file in the same folder as the server is running.
## Recommendation
Upgrade to version 0.5.4 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xf27-jqwv-gf3r for updates pertaining to this vulnerability.
Vendor References
- GHSA-xf27-jqwv-gf3r -
github.com/advisories/GHSA-xf27-jqwv-gf3r
CVEs related to QID 983067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xf27-jqwv-gf3r | larvitbase-api |
|