Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc4dnAtNmh2NC1tNjdj
Command Injection in entitlements
Versions of entitlements
prior to 1.3.0 are vulnerable to Command Injection. The package does not validate input on the entitlements
function and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system.
Recommendation
Upgrade to version 1.3.0 or later.
Permalink: https://github.com/advisories/GHSA-g8vp-6hv4-m67cJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc4dnAtNmh2NC1tNjdj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 4 years ago
Updated: over 1 year ago
Identifiers: GHSA-g8vp-6hv4-m67c
References:
- https://hackerone.com/reports/341869
- https://www.npmjs.com/advisories/998
- https://github.com/advisories/GHSA-g8vp-6hv4-m67c
Affected Packages
npm:entitlements
Dependent packages: 4Dependent repositories: 15
Downloads: 968 last month
Affected Version Ranges: < 1.3.0
Fixed in: 1.3.0
All affected versions: 1.0.0, 1.1.0, 1.2.0
All unaffected versions: 1.3.0