CVE-2018-13797
Command Injection in macaddress
9.8
CRITICAL
CVSS 3.1
EPSS 6.7%
Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
How to fix CVE-2018-13797
To remediate CVE-2018-13797, upgrade the affected package to a fixed version below.
- Debian/node-macaddress—upgrade to 0.2.9-1 or later
- npm/macaddress—upgrade to 0.2.9 or later
Is CVE-2018-13797 being exploited?
Moderate — EPSS is 6.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.2.9-1
- from 0, < 0.2.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |