Description
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
Remediation
References
https://github.com/skoranga/node-dns-sync/issues/5
https://nodesecurity.io/advisories/523
Related Vulnerabilities
CVE-2023-30094 Vulnerability in npm package total4
CVE-2022-41946 Vulnerability in maven package org.postgresql:postgresql
CVE-2022-39231 Vulnerability in npm package parse-server
CVE-2021-41580 Vulnerability in npm package passport-oauth2
CVE-2014-0168 Vulnerability in maven package org.jolokia:jolokia-core