Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20748
HistoryJul 10, 2019 - 4:47 a.m.

Command Injection

2019-07-1004:47:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.008 Low

EPSS

Percentile

82.2%

dns-sync is vulnerable to command injection. Lack of input validation allows an attacker to submit input into resolve() method, whcih would allow arbitrary command injection on the system.

CPENameOperatorVersion
dns-syncle0.1.2

0.008 Low

EPSS

Percentile

82.2%