← Back

CVE-2024-21488

nvd nist
Published: Jan 30, 2024Modified: Jul 4, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.

Affected (1)

Products: Forkhq: Network
1 product
Network
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.7.0

References (11)

Timeline

No history available yet.