CVE-2020-7620: OS Command Injection
Published Apr 2, 2020
·Updated
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
Affected Software
1 affected component
NetEase Pomelo-monitor Node.js<=0.3.7
Event History
Apr 2, 2020
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7620?
CVE-2020-7620 is considered a high severity vulnerability due to the risk of command injection.
2
How do I fix CVE-2020-7620?
To fix CVE-2020-7620, update pomelo-monitor to version 0.3.8 or later which addresses the command injection vulnerability.
3
Is CVE-2020-7620 a remote attack vulnerability?
Yes, CVE-2020-7620 can be exploited remotely by injecting commands through the vulnerable parameters.
4
What software does CVE-2020-7620 affect?
CVE-2020-7620 affects versions of pomelo-monitor up to 0.3.7, which is used in Node.js applications.
5
How can I mitigate risks associated with CVE-2020-7620?
To mitigate risks from CVE-2020-7620, ensure that you do not use the affected versions of pomelo-monitor and implement input validation on parameters.