GHSA-8gr3-2gjw-jj7g

Suggest an improvement
Source
https://github.com/advisories/GHSA-8gr3-2gjw-jj7g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-8gr3-2gjw-jj7g/GHSA-8gr3-2gjw-jj7g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8gr3-2gjw-jj7g
Published
2022-03-16T23:54:33Z
Modified
2022-03-16T23:54:33Z
Summary
Hidden functionality in node-ipc
Details

The package node-ipc version 9.2.2 is vulnerable to hidden functionality that was introduced by the maintainer. The package uses a dependency that writes a file to disk that does not pertain to the functionality of the package and is not included in versions < 9.2.2.

Database specific
{
    "cwe_ids":  [
        "CWE-912"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-03-16T23:54:33Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / node-ipc

Package

Affected ranges

Affected versions

9.*
9.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-8gr3-2gjw-jj7g/GHSA-8gr3-2gjw-jj7g.json"