First published: Thu May 28 2020(Updated: )
node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Node-dns-sync Project Node-dns-sync | <0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11079 is a vulnerability in the node-dns-sync npm module that allows execution of arbitrary commands, potentially leading to remote code execution.
The severity of CVE-2020-11079 is critical, with a CVSS score of 9.8.
CVE-2020-11079 can be exploited by a client of the library calling the vulnerable method with untrusted input, allowing execution of arbitrary commands.
Versions up to and exclusive of 0.2.1 of the node-dns-sync npm module are affected by CVE-2020-11079.
CVE-2020-11079 has been fixed in version 0.2.1 of the node-dns-sync npm module.