openssl@1.1.0 vulnerabilities

Nodejs openssl wrapper

  • latest version

    2.0.0

  • first published

    11 years ago

  • latest version published

    3 years ago

  • deprecated

    Package is deprecated

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the openssl package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    openssl is a Nodejs openssl wrapper

    Affected versions of this package are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') through the openssl() function due to accepting an opts argument which has verb field. An attacker can execute arbitrary commands by exploiting this vulnerability.

    Note:

    This vulnerability only affects products that are no longer supported by the maintainer.

    How to fix Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')?

    There is no fixed version for openssl.

    *