VDB
Sign up
CRITICAL

GHSA-jcw8-r9xm-32c6

Command Injection in dns-sync

Quick fix

GHSA-jcw8-r9xm-32c6 — dns-sync: upgrade to the fixed version with the command below.

npm install dns-sync@0.1.1

Details

Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method.

## Recommendation

- Use an alternative dns resolver - Do not allow untrusted input into `dns-sync.resolve()`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dns-sync
Introduced in: 0Fixed in: 0.1.1
Fixnpm install dns-sync@0.1.1

References