Lucene search

K
nodejsCristian-Alexandru StaicuNODEJS:523
HistorySep 06, 2017 - 11:32 p.m.

Command Injection

2017-09-0623:32:56
Cristian-Alexandru Staicu
www.npmjs.com
90

0.008 Low

EPSS

Percentile

82.2%

Overview

Affected versions of dns-sync have an arbitrary command execution vulnerability in the resolve() method.

Recommendation

  • Use an alternative dns resolver
  • Do not allow untrusted input into dns-sync.resolve()

References

CPENameOperatorVersion
dns-synclt0.1.1

0.008 Low

EPSS

Percentile

82.2%