Description
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
Remediation
References
https://github.com/tj/node-growl/issues/60
https://github.com/tj/node-growl/pull/61
https://nodesecurity.io/advisories/146
Related Vulnerabilities
CVE-2016-4055 Vulnerability in maven package org.webjars.npm:moment
CVE-2015-5237 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2018-16487 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2020-2238 Vulnerability in maven package org.jenkins-ci.plugins:git-parameter
CVE-2017-13098 Vulnerability in maven package com.madgag.spongycastle:bctls-jdk15on