QID 983162
QID 983162: Nodejs (npm) Security Update for dns-sync (GHSA-jcw8-r9xm-32c6)
Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method.
## Recommendation
- Use an alternative dns resolver
- Do not allow untrusted input into `dns-sync.resolve()`
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jcw8-r9xm-32c6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-jcw8-r9xm-32c6 -
github.com/advisories/GHSA-jcw8-r9xm-32c6
CVEs related to QID 983162
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jcw8-r9xm-32c6 | dns-sync |
|