VDB
Sign up
CRITICAL9.8

GHSA-w5mp-8p8w-mhh8

Command injection in connection-tester

Quick fix

GHSA-w5mp-8p8w-mhh8 — connection-tester: upgrade to the fixed version with the command below.

npm install connection-tester@0.2.1

Details

This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. Affected versions of this package are vulnerable to Command Injection

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/connection-tester
Introduced in: 0Fixed in: 0.2.1
Fixnpm install connection-tester@0.2.1

References