Arbitrary Command Injection Affecting printer package, versions <0.2.1
Threat Intelligence
EPSS
0.4% (75th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID npm:printer:20140306
- published 6 Mar 2014
- disclosed 6 Mar 2014
- credit Adam Baldwin
How to fix?
Upgrade to version > 0.0.1 which is available on github at https://github.com/tojocky/node-printer
Overview
printer does not sanitize command arguments properly in the printDirect()
function. If untrusted client input is passed in, command injection is possible.
Source: Node Security Project
References
- https://github.com/tojocky/node-printer
- https://github.com/tojocky/node-printer/commit/e001e38738c17219a1d9dd8c31f7d82b9c0013c7
Special thanks to Wes Cruver for providing a pull request!
CVSS Scores
version 3.1