Description
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Remediation
References
https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
https://github.com/scravy/node-macaddress/pull/20/
https://github.com/scravy/node-macaddress/releases/tag/0.2.9
https://news.ycombinator.com/item?id=17283394
Related Vulnerabilities
CVE-2020-28462 Vulnerability in npm package ion-parser
CVE-2021-4329 Vulnerability in maven package org.webjars.npm:json-logic-js
CVE-2020-9488 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2022-25893 Vulnerability in npm package vm2
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-common_2.11