Description
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Remediation
References
https://github.com/skoranga/node-dns-sync/issues/5
https://nodesecurity.io/advisories/523
Related Vulnerabilities
CVE-2020-36049 Vulnerability in npm package socket.io-parser
CVE-2022-25349 Vulnerability in npm package materialize-css
CVE-2020-36629 Vulnerability in npm package httpster
CVE-2023-39013 Vulnerability in maven package no.priv.garshol.duke:duke
CVE-2022-36091 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates