Vulnerability Description
All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Isof Project | Isof | <= 0.0.4 |
Related Weaknesses (CWE)
References
- https://snyk.io/vuln/SNYK-JS-LSOF-543632ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-LSOF-543632ExploitThird Party Advisory
FAQ
What is CVE-2019-10783?
CVE-2019-10783 is a vulnerability with a CVSS score of 9.8 (CRITICAL). All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.
How severe is CVE-2019-10783?
CVE-2019-10783 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-10783?
Check the references section above for vendor advisories and patch information. Affected products include: Isof Project Isof.