dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
References
Link | Resource |
---|---|
https://nodesecurity.io/advisories/523 | Third Party Advisory |
https://github.com/skoranga/node-dns-sync/issues/5 | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-06-06 19:29
Updated : 2019-10-09 16:24
NVD link : CVE-2017-16100
Mitre link : CVE-2017-16100
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
dns-sync_project
- dns-sync