GHSA-8j9v-qhp4-wv55

Suggest an improvement
Source
https://github.com/advisories/GHSA-8j9v-qhp4-wv55
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8j9v-qhp4-wv55/GHSA-8j9v-qhp4-wv55.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8j9v-qhp4-wv55
Aliases
Published
2022-05-24T17:21:39Z
Modified
2023-11-08T04:00:14Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Node-Traceroute RCE Vulnerability
Details

The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

Database specific
{
    "cwe_ids":  [
        "CWE-74"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-07-19T23:28:29Z",
    "nvd_published_at":  "2020-06-25T17:15:00Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / traceroute

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8j9v-qhp4-wv55/GHSA-8j9v-qhp4-wv55.json"