Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22721
HistoryMar 17, 2020 - 6:03 a.m.

OS Command Injection

2020-03-1706:03:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.01 Low

EPSS

Percentile

83.8%

closure-compiler-stream is vulnerable to OS command injection. The args options are passed to the exec function without any validation and sanitization, allowing an attacker to inject and execute arbitrary OS commands.

CPENameOperatorVersion
closure-compiler-streamle0.1.15

0.01 Low

EPSS

Percentile

83.8%

Related for VERACODE:22721