bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.6epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
nfriedly · bestzipReferencias
https://github.com/nfriedly/node-bestziphttps://github.com/nfriedly/node-bestzip/blob/v3.0.2/lib/bestzip.jshttps://github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aafhttps://github.com/nfriedly/node-bestzip/security/advisories/GHSA-p87m-9567-rgcchttps://github.com/nfriedly/node-bestzip/security/advisories/GHSA-xhwx-rch4-ph2vhttps://www.npmjs.com/package/bestziphttps://www.vulncheck.com/advisories/bestzip-2.2.6-and-3.0.2-argument-injection-via-the-native-zip-destination