CRITICAL
GHSA-jcw8-r9xm-32c6
Command Injection in dns-sync
Quick fix
GHSA-jcw8-r9xm-32c6 — dns-sync: upgrade to the fixed version with the command below.
npm install dns-sync@0.1.1Details
Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method.
## Recommendation
- Use an alternative dns resolver - Do not allow untrusted input into `dns-sync.resolve()`
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16100[ADVISORY]
- https://github.com/skoranga/node-dns-sync/issues/1[WEB]
- https://github.com/skoranga/node-dns-sync/issues/1)[WEB]
- https://github.com/skoranga/node-dns-sync/issues/5[WEB]
- https://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d[WEB]
- https://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d)))[WEB]
- https://github.com/advisories/GHSA-jcw8-r9xm-32c6[ADVISORY]
- https://www.npmjs.com/advisories/153[WEB]
- https://www.npmjs.com/advisories/523[WEB]