Headline
GHSA-75w2-qv55-x7fv: openssl npm package vulnerable to command execution
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as “a nonsense wrapper with no real purpose” by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
openssl npm package vulnerable to command execution
Moderate severity GitHub Reviewed Published Nov 23, 2023 to the GitHub Advisory Database • Updated Nov 27, 2023
Related news
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.