CVE-2024-21488

CVSS V2 None CVSS V3 None
Description
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.
Overview
  • CVE ID
  • CVE-2024-21488
  • Assigner
  • snyk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-30T05:00:01.547Z
  • Last Modified Date
  • 2024-03-06T14:09:56.189Z
History
Created Old Value New Value Data Type Notes
2024-06-26 15:04:45 Added to TrackCVE