CVE-2024-27980
HIGH8.1EPSS 0.37%Published: 1/10/2025Modified: 4/3/2025
Description
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
Affected packages (2)
- Bitnami/nodefrom 0, < 18.20.2, >= 19.0.0, < 20.12.2, >= 21.0.0, < 21.7.3
- Bitnami/node-minfrom 0, < 18.20.2, >= 19.0.0, < 20.12.2, >= 21.0.0, < 21.7.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (6)
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5MZN6PFXHTCCUENAKZXTGWPKUAHI6E2W/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/JUWBYDVCUSCX7YWTBX75LADMCVYFBGKU/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2024-27980
- WEBhttp://www.openwall.com/lists/oss-security/2024/04/10/15
- WEBhttp://www.openwall.com/lists/oss-security/2024/07/11/6
- WEBhttp://www.openwall.com/lists/oss-security/2024/07/19/3