QID 983206
QID 983206: Nodejs (npm) Security Update for summit (GHSA-cwcp-6c48-fm7m)
Affected versions of `summit` allow attackers to execute arbitrary commands via collection names when using the `PouchDB` driver.
## Recommendation
No direct patch is available at this time.
Currently, the best option to mitigate the issue is to avoid using the `PouchDB` driver, as the package author has abandoned this feature entirely.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cwcp-6c48-fm7m for updates pertaining to this vulnerability.
Vendor References
- GHSA-cwcp-6c48-fm7m -
github.com/advisories/GHSA-cwcp-6c48-fm7m
CVEs related to QID 983206
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cwcp-6c48-fm7m | summit |
|