Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Remediation
References
https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
https://github.com/scravy/node-macaddress/pull/20/
https://github.com/scravy/node-macaddress/releases/tag/0.2.9
https://news.ycombinator.com/item?id=17283394
Related Vulnerabilities
CVE-2023-25499 Vulnerability in maven package com.vaadin:vaadin
CVE-2017-3523 Vulnerability in maven package mysql:mysql-connector-java
CVE-2023-46298 Vulnerability in npm package next
CVE-2022-31172 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2023-6293 Vulnerability in npm package sequelize-typescript