GHSA-f478-xwv9-p93q
Dashboard / Vulnerabilities / GHSA-f478-xwv9-p93q
GHSA-f478-xwv9-p93q
Summary: Duplicate Advisory: Kerberos for NodeJS allows DLL Injection
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-m2mx-rfpw-jghv. This link is maintained to preserve external references. ## Original Description The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-13110, https://medium.com/@kiddo_Ha3ker/dll-injection-attack-in-kerberos-npm-package-cb4b32031cd, https://www.npmjs.com/advisories/1514
Affected packages
Package
Name: kerberos
Purl: pkg:npm/kerberos
Affected ranges
Type: SEMVER
Events:
