ZeroHour

CVE-2017-16042

CVSS 3.0
9.8 critical
EPSS
4%p91
Published
()
Modified
Description

Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

Vendors
growl project
Products
growl
Weakness
CWE-94, CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.