Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBwNTctbXFtaC00NGg3

Command Injection in macaddress

All versions of macaddress are vulnerable to command injection. For this vulnerability to be exploited an attacker needs to control the iface argument to the one method.

Recommendation

Update to version 0.2.9 or later.

Permalink: https://github.com/advisories/GHSA-pp57-mqmh-44h7
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBwNTctbXFtaC00NGg3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 5 years ago
Updated: over 1 year ago


CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-pp57-mqmh-44h7, CVE-2018-13797
References: Repository: https://github.com/scravy/node-macaddress
Blast Radius: 51.7

Affected Packages

npm:macaddress
Dependent packages: 115
Dependent repositories: 190,665
Downloads: 836,374 last month
Affected Version Ranges: < 0.2.9
Fixed in: 0.2.9
All affected versions: 0.2.6, 0.2.7, 0.2.8
All unaffected versions: 0.2.9, 0.3.0, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.5.0, 0.5.1, 0.5.2, 0.5.3