Vulnerabilities/

Command Injection in soletta-dev-app

Severity:
High

Description

All versions of soletta-dev-app are vulnerable to Command Injection. The package does not validate user input on the /api/service/status API endpoint, passing contents of the service query parameter to an exec call. This may allow attackers to run arbitrary commands in the system.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
soletta-dev-app
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing