Command injection in connection-tester
Critical severity
GitHub Reviewed
Published
Dec 17, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 16, 2020
Reviewed
Dec 17, 2020
Published to the GitHub Advisory Database
Dec 17, 2020
Last updated
Feb 1, 2023
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. Affected versions of this package are vulnerable to Command Injection
References