CVE-2020-7730

The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bestzip_project:bestzip:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://github.com/nfriedly/node-bestzip/commit/45d4a901478c6a8f396c8b959dd6cf8fd3f955b6 - Patch, Third Party Advisory () https://github.com/nfriedly/node-bestzip/commit/45d4a901478c6a8f396c8b959dd6cf8fd3f955b6 - Patch, Third Party Advisory
References () https://snyk.io/vuln/SNYK-JS-BESTZIP-609371 - Patch, Third Party Advisory () https://snyk.io/vuln/SNYK-JS-BESTZIP-609371 - Patch, Third Party Advisory

Information

Published : 2020-09-04 10:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7730

Mitre link : CVE-2020-7730

CVE.ORG link : CVE-2020-7730


JSON object : View

Products Affected

bestzip_project

  • bestzip
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')