Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdqcjQtMmpndy1obXY4

Command Injection in whereis

Versions of whereis before 0.4.1 are vulnerable to command injection if untrusted user input is passed into whereis.

Recommendation

Update to version 0.4.1 or later.

Permalink: https://github.com/advisories/GHSA-wjr4-2jgw-hmv8
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdqcjQtMmpndy1obXY4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 5 years ago
Updated: 8 months ago


CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-wjr4-2jgw-hmv8, CVE-2018-3772
References: Repository: https://github.com/vvo/node-whereis
Blast Radius: 21.0

Affected Packages

npm:whereis
Dependent packages: 17
Dependent repositories: 138
Downloads: 3,991 last month
Affected Version Ranges: < 0.4.1
Fixed in: 0.4.1
All affected versions: 0.0.1, 0.0.2, 0.2.0, 0.2.1, 0.3.0, 0.4.0
All unaffected versions: 0.4.1, 1.0.0