Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlqbTMtNTgzNS01Mzdt
Command Injection in apex-publish-static-files
Versions of apex-publish-static-files
before 2.0.1 are vulnerable to command injection. This is exploitable if user input is passed into the connectString
option in the publish
method.
Recommendation
Update to version 2.0.1 or later.
Permalink: https://github.com/advisories/GHSA-9jm3-5835-537mJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlqbTMtNTgzNS01Mzdt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 6 years ago
Updated: about 1 year ago
CVSS Score: 10.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Identifiers: GHSA-9jm3-5835-537m, CVE-2018-16462
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-16462
- https://hackerone.com/reports/405694
- https://github.com/advisories/GHSA-9jm3-5835-537m
- https://github.com/nodejs/security-wg/blob/master/vuln/npm/475.json
- https://www.npmjs.com/advisories/718
Affected Packages
npm:apex-publish-static-files
Dependent packages: 7Dependent repositories: 5
Downloads: 143 last month
Affected Version Ranges: < 2.0.1
Fixed in: 2.0.1
All affected versions: 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 2.0.0
All unaffected versions: 2.0.1, 2.0.2, 2.0.3