node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "0.2.1"
}
],
"cpes": [
"cpe:2.3:a:node-dns-sync_project:node-dns-sync:*:*:*:*:*:*:*:*"
],
"vendor_product": "node-dns-sync_project:node-dns-sync",
"source": "CPE_RANGE"
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "0.2.0"
}
]
}
]
}