

Rewterz Threat Alert – Mirai Botnet – Active IOCs
May 13, 2022
Rewterz Threat Advisory – CVE-2022-30523 – Trend Micro Password Manager Vulnerability
May 16, 2022
Rewterz Threat Alert – Mirai Botnet – Active IOCs
May 13, 2022
Rewterz Threat Advisory – CVE-2022-30523 – Trend Micro Password Manager Vulnerability
May 16, 2022Severity
High
Analysis Summary
CVE-2022-25865
Node.js workspace-tools module could allow a remote attacker to execute arbitrary commands on the system, caused by a git argument injection flaw in the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function. By sending a specially-crafted request using the remote and remoteBranch parameters, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Impact
- Command Execution
Indicators Of Compromise
CVE
- CVE-2022-25865
Affected Vendors
- Node.js
Affected Products
Node.js workspace-tools 0.18.3
Remediation
Upgrade to the latest version of workspace tools, available from the workspace-tools GIT Repository.