Command Injection in dns-sync
Critical severity
GitHub Reviewed
Published
Jul 18, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Jul 18, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Affected versions of
dns-sync
have an arbitrary command execution vulnerability in theresolve()
method.Recommendation
dns-sync.resolve()
References