CVE-2017-16100
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 5.1%
exploitation probability
5.1%top 8% of all CVEs
observed exploitation
nono source reports it
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Affected products
HackerOne · dns-sync node module