Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35883
HistoryJun 06, 2022 - 2:59 a.m.

OS Command Injection

2022-06-0602:59:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.003 Low

EPSS

Percentile

69.7%

docker-tester is vulnerable to OS command injection. The vulnerability exists in the port attribute in the getExternalPort function of docker-compose.js, allowing an attacker to inject and execute malicious commands through the docker-compose.yml by providing shell meta characters.

CPENameOperatorVersion
docker-testerle1.2.2
docker-testerle1.2.2

0.003 Low

EPSS

Percentile

69.7%

Related for VERACODE:35883