Lucene search

K
osvGoogleOSV:GHSA-Q5PQ-PGRV-FH89
HistoryOct 24, 2017 - 6:33 p.m.

dns-sync command injection vulnerability

2017-10-2418:33:36
Google
osv.dev
9

0.003 Low

EPSS

Percentile

65.2%

The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

CPENameOperatorVersion
dns-synclt0.1.1

0.003 Low

EPSS

Percentile

65.2%

Related for OSV:GHSA-Q5PQ-PGRV-FH89