Skip to content
COOEY

EXPOSURES › CVE-2024-21488

CVE-2024-21488

HIGH
DETAIL
SourceNVD · cve Published2024-01-30 CVSS7.3 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-21488 ↗
⚡ RCE SHAME 40/100 rce

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

PLAYERS IMPLICATED
DESCRIPTION

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.