Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Remote Code Execution (RCE) vulnerabilities in an interactive lesson.
Start learningUpgrade @whyour/qinglong to version 2.20.2-0 or higher.
@whyour/qinglong is a Timed task management platform supporting Python3, JavaScript, Shell, Typescript
Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the application's Express.js middleware that allows to rewrite /open/* to /api/$1 api interface. A remote attacker can access the server’s initialisation flow after the server has already been configured, allowing them to reset the admin password and obtain administrative access without authorisation.