Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Remediation
References
https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
https://github.com/scravy/node-macaddress/pull/20/
https://github.com/scravy/node-macaddress/releases/tag/0.2.9
https://news.ycombinator.com/item?id=17283394
Related Vulnerabilities
CVE-2020-27216 Vulnerability in maven package org.mortbay.jetty:jetty
CVE-2023-50730 Vulnerability in maven package org.typelevel:grackle-core_sjs1_3
CVE-2018-8088 Vulnerability in maven package org.slf4j:slf4j-ext
CVE-2021-43797 Vulnerability in maven package io.netty:netty-codec-http
CVE-2020-15813 Vulnerability in maven package org.graylog2:graylog2-server