GHSA-c9j3-wqph-5xx9

Source
https://github.com/advisories/GHSA-c9j3-wqph-5xx9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-c9j3-wqph-5xx9/GHSA-c9j3-wqph-5xx9.json
Aliases
Published
2018-09-17T20:43:34Z
Modified
2023-11-08T04:00:20.228557Z
Details

Versions of egg-scripts before 2.8.1 are vulnerable to command injection. This is only exploitable if a malicious argument is provided on the command line.

Example: eggctl start --daemon --stderr='/tmp/eggctl_stderr.log; touch /tmp/malicious'

Recommendation

Update to version 2.8.1 or later.

References

Affected packages

npm / egg-scripts

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
2.8.1