CVE-2017-16024

The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:sync-exec_project:sync-exec:*:*:*:*:*:node.js:*:*

Configuration 2 (hide)

cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*

Information

Published : 2018-06-04 12:29

Updated : 2019-10-09 16:24


NVD link : CVE-2017-16024

Mitre link : CVE-2017-16024


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

nodejs

  • node.js

sync-exec_project

  • sync-exec