Rewterz
Rewterz Threat Advisory – CVE-2021-23001 – F5 BIG-IP (Advanced WAF, ASM) security bypass
April 1, 2021
Rewterz
Rewterz Threat Alert – Russian APT Gamaredon Using Template Injection
April 1, 2021

Rewterz Threat Advisory – CVE-2021-23348 – Node.js portprocesses module command execution

Severity

Medium

Analysis Summary

CVE-2021-23348

Node.js portprocesses module could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by improper input validation by the killProcess function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.

Impact

Gain access

Affected Vendors

NodeJs

Affected Products

  • Node.js portprocesses 1.0.4
  • Node.js portprocesses 1.0.3

Remediation

Upgrade to the latest version of portprocesses (1.0.5 or later)