Remote Code Execution in node-os-utils
High severity
GitHub Reviewed
Published
Jun 11, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 11, 2019
Published to the GitHub Advisory Database
Jun 11, 2019
Last updated
Jan 9, 2023
Versions of
node-os-utils
prior to 1.1.0 are vulnerable to Remote Code Execution. Due to insufficient input validation an attacker could run arbitrary commands on the server thus rendering the package vulnerable to Remote Code Execution.Recommendation
Upgrade to version 1.1.0 or later.
References