GHSA-xhjx-mfr6-9rr4

Suggest an improvement
Source
https://github.com/advisories/GHSA-xhjx-mfr6-9rr4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-xhjx-mfr6-9rr4/GHSA-xhjx-mfr6-9rr4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xhjx-mfr6-9rr4
Published
2020-09-01T21:20:28Z
Modified
2020-08-31T18:33:52Z
Summary
Command Injection in samsung-remote
Details

Versions of samsung-remote before 1.3.5 are vulnerable to command injection. This vulnerability is exploitable if user input is passed into the ip option of the package constructor.

Recommendation

Update to version 1.3.5 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:33:52Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / samsung-remote

Package

Name
samsung-remote
View open source insights on deps.dev
Purl
pkg:npm/samsung-remote

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-xhjx-mfr6-9rr4/GHSA-xhjx-mfr6-9rr4.json"