Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29653
HistoryMar 10, 2021 - 6:06 a.m.

OS Command Injection

2021-03-1006:06:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
os command injection
react-dev-utils
software vulnerability
child_process.execfilesync
getprocessidonport

EPSS

0.002

Percentile

54.5%

react-dev-utils is vulnerable to OS command injection. An attacker is able to inject and execute arbitrary OS commands on the host OS due to the usage of child_process.execFileSync() in the function getProcessIdOnPort.

EPSS

0.002

Percentile

54.5%