Command injection in node-dns-sync
High severity
GitHub Reviewed
Published
May 22, 2020
in
skoranga/node-dns-sync
•
Updated Feb 1, 2023
Description
Reviewed
May 28, 2020
Published to the GitHub Advisory Database
May 28, 2020
Published by the National Vulnerability Database
May 28, 2020
Last updated
Feb 1, 2023
dns-sync through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input.
References