CVE-2017-16100

EPSS 5.3%

Command Injection in dns-sync

發布日:2018/7/18修改日:2023/11/8

描述

Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method. ## Recommendation - Use an alternative dns resolver - Do not allow untrusted input into `dns-sync.resolve()`

受影響套件(1)

參考連結(9)