GHSA-2548-q746-x5x6
Dashboard / Vulnerabilities / GHSA-2548-q746-x5x6
Summary: Code injection in port-killer
Details: This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command touch success to be executed, leading to the creation of a file called success.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-23359, https://github.com/tylerjpeterson/port-killer/blob/1ca3a99ad80cc9ed5498d12b185189c10329025b/index.js%23L19, https://snyk.io/vuln/SNYK-JS-PORTKILLER-1078533
Affected packages
Package
Name: port-killer
Purl: pkg:npm/port-killer
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
