Back

CRITICAL

nodejs-macaddress: improper input validation leading to command injection

Published Jul 10, 2018

Description

The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

Affected products

Remediation

Red Hat statement

Red Hat Quay uses the macaddress module, but only as a development dependency, not at runtime reducing the impact on that product to low.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 10, 2018
Updated Sep 16, 2024
Reserved Jul 10, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Jun 11, 2018
GHSA-PP57-MQMH-44H7