Description
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Remediation
References
https://github.com/skoranga/node-dns-sync/issues/5
https://nodesecurity.io/advisories/523
Related Vulnerabilities
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-44908 Vulnerability in npm package sails
CVE-2018-19837 Vulnerability in npm package node-sass
CVE-2022-35980 Vulnerability in maven package org.opensearch.plugin:opensearch-security