ZeroHour

CVE-2020-8149

PoC
CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

Vendors
logkitty project
Products
logkitty
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.