Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Remediation
References
https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
https://github.com/scravy/node-macaddress/pull/20/
https://github.com/scravy/node-macaddress/releases/tag/0.2.9
https://news.ycombinator.com/item?id=17283394
Related Vulnerabilities
CVE-2019-18394 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2021-23484 Vulnerability in npm package zip-local
CVE-2021-32859 Vulnerability in npm package baremetrics-calendar
CVE-2017-1000188 Vulnerability in maven package org.webjars.npm:ejs