Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc4dnAtNmh2NC1tNjdj
Command Injection in entitlements
Versions of entitlements
prior to 1.3.0 are vulnerable to Command Injection. The package does not validate input on the entitlements
function and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system.
Recommendation
Upgrade to version 1.3.0 or later.
Permalink: https://github.com/advisories/GHSA-g8vp-6hv4-m67cJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc4dnAtNmh2NC1tNjdj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 3 years ago
Updated: 9 months ago
Identifiers: GHSA-g8vp-6hv4-m67c
References:
- https://hackerone.com/reports/341869
- https://www.npmjs.com/advisories/998
- https://github.com/advisories/GHSA-g8vp-6hv4-m67c
Affected Packages
npm:entitlements
Versions: < 1.3.0Fixed in: 1.3.0