QID 995871
Date Published: 2023-11-16
QID 995871: NodeJs (Npm) Security Update for chromedriver (GHSA-hm92-vgmw-qfmx)
Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unauthorized access and potentially malicious actions on the host system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hm92-vgmw-qfmx for updates and patch information.
Vendor References
- GHSA-hm92-vgmw-qfmx -
github.com/advisories/GHSA-hm92-vgmw-qfmx
CVEs related to QID 995871
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hm92-vgmw-qfmx | chromedriver |
|