forked from OWASP/NodeGoat
-
Notifications
You must be signed in to change notification settings - Fork 0
CVE-2017-16042 @ Npm-growl-1.9.2 #137
Copy link
Copy link
Open
Description
Vulnerable Package issue exists @ Npm-growl-1.9.2 in branch master
Growl adds growl notification support to nodejs. Growl before 1.10.0 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Namespace: RobertMickleCx
Repository: NodeGoat
Repository Url: https://github.com/RobertMickleCx/NodeGoat
CxAST-Project: RobertMickleCx/NodeGoat
CxAST platform scan: 4cad0b9d-cbe1-4acd-bb82-244764df9dbd
Branch: master
Application: NodeGoat
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-77
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: HIGH
References
Advisory
Issue
Pull request
Pull request
Commit
Advisory
Reactions are currently unavailable