Skip to content

Commit 8a468a3

Browse files
authored
vuln: add latest sec release (#1278)
1 parent 96ad6cc commit 8a468a3

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

vuln/core/141.json

+12
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
{
2+
"cve": [
3+
"CVE-2024-27982"
4+
],
5+
"vulnerable": "18.x || 20.x || 21.x",
6+
"patched": "^18.20.2 || ^20.12.2 || ^21.7.3",
7+
"ref": "https://nodejs.org/en/blog/vulnerability/april-2024-security-releases-2/",
8+
"overview": "Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.",
9+
"affectedEnvironments": [
10+
"win32"
11+
]
12+
}

0 commit comments

Comments
 (0)