← volver
CVE-2020-5282highCWE-78

arbitrary shell execution in Nick Chan Bot

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 7.2epss 1.2%
probabilidad de explotación
1.2%top 34% de las CVE
explotación observada
noninguna fuente lo reporta
In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrary shell execution,which can compromise the bot This is patched in version 1.0.0-beta
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Productos afectados
Nick Chan · nickchanbot