Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Remediation
References
https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
https://github.com/scravy/node-macaddress/pull/20/
https://github.com/scravy/node-macaddress/releases/tag/0.2.9
https://news.ycombinator.com/item?id=17283394
Related Vulnerabilities
CVE-2013-6397 Vulnerability in maven package org.apache.solr:solr-core
CVE-2021-34435 Vulnerability in npm package @theia/mini-browser
CVE-2016-1000352 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2023-26920 Vulnerability in maven package org.webjars.npm:fast-xml-parser
CVE-2016-15026 Vulnerability in maven package com.googlecode.plist:dd-plist