Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: code injection in 0.1.4 - CVE-2019-15597 #6

Open
otisg opened this issue Feb 18, 2020 · 1 comment
Open

Security: code injection in 0.1.4 - CVE-2019-15597 #6

otisg opened this issue Feb 18, 2020 · 1 comment

Comments

@otisg
Copy link

otisg commented Feb 18, 2020

@adriano-di-giovanni any chance you could release a new version of node-df with a fix for this?

CVE-2019-15597
high severity
Vulnerable versions: = 0.1.4
Patched version: No fix
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.

https://snyk.io/vuln/npm:node-df
https://snyk.io/vuln/SNYK-JS-NODEDF-536779
https://hackerone.com/reports/703412

@megastef
Copy link

I think removing semicolons, & and | characters in files option should avoid executing other commands than df. So a a fix is probably easy. Would a PR help?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants