QID 984067
QID 984067: Nodejs (npm) Security Update for whereis (GHSA-wjr4-2jgw-hmv8)
Versions of `whereis` before 0.4.1 are vulnerable to command injection if untrusted user input is passed into `whereis`. ## Recommendation Update to version 0.4.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wjr4-2jgw-hmv8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-wjr4-2jgw-hmv8 -
github.com/advisories/GHSA-wjr4-2jgw-hmv8
CVEs related to QID 984067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wjr4-2jgw-hmv8 | whereis |
|