CVE-2017-16100
CVE-2017-16100
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Affected products
HackerOne · dns-sync node moduleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →