Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Remediation
References
https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
https://github.com/scravy/node-macaddress/pull/20/
https://github.com/scravy/node-macaddress/releases/tag/0.2.9
https://news.ycombinator.com/item?id=17283394
Related Vulnerabilities
CVE-2021-4307 Vulnerability in maven package org.webjars.bower:baobab
CVE-2013-7315 Vulnerability in maven package org.springframework:spring-web
CVE-2020-15250 Vulnerability in maven package junit:junit
CVE-2022-3971 Vulnerability in npm package matrix-appservice-irc
CVE-2021-41303 Vulnerability in maven package org.apache.shiro:shiro-core