CRITICAL9.8
GHSA-8j9v-qhp4-wv55
Node-Traceroute RCE Vulnerability
Details
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the `Child.exec()` method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/traceroute
Introduced in:
0No fixed version published yet for traceroute (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-21268[ADVISORY]
- https://github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386f[WEB]
- https://github.com/jaw187/node-traceroute[PACKAGE]
- https://github.com/jaw187/node-traceroute/tags[WEB]
- https://medium.com/@shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3[WEB]
- https://snyk.io/vuln/npm:traceroute:20160311[WEB]
- https://www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-Rcpy[WEB]
- https://www.npmjs.com/advisories/1465[WEB]
- https://www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package[WEB]