openssl@1.1.0 vulnerabilities

Nodejs openssl wrapper

Direct Vulnerabilities

Known vulnerabilities in the openssl package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

openssl is a Nodejs openssl wrapper

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') through the openssl() function due to accepting an opts argument which has verb field. An attacker can execute arbitrary commands by exploiting this vulnerability.

Note:

This vulnerability only affects products that are no longer supported by the maintainer.

How to fix Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')?

There is no fixed version for openssl.

*