Arbitrary Command Injection Vulnerability in Child Process Functions of Software
CVE-2024-27980
What is CVE-2024-27980?
This vulnerability arises from improper handling of batch files in the child_process.spawn and child_process.spawnSync functions. A malicious actor can manipulate command line arguments to inject arbitrary commands, leading to unintended code execution. This can occur even when the shell option is disabled, potentially allowing for unauthorized actions on the affected system. Organizations utilizing this software are advised to review their security measures and apply patches as soon as available to mitigate risks associated with this vulnerability.
Affected Version(s)
Node.js 21.7.0
Node.js 20.11.1
Node.js 18.19.1
News Articles
Node.js์์ ์์ ์ฝ๋ ์คํ ์ทจ์ฝ์ ๋ฐ๊ฒฌ
Node.js์์ ์์ ์ฝ๋ ์คํ ์ทจ์ฝ์ ์ด ๋ฐ๊ฒฌ๋ผ ์ด์ฉ์๋ค์ ๊ฐ๋ณํ ์ฃผ์๊ฐ ์๊ตฌ๋๋ค. ์ด์ ๊ด๋ จ ํ๊ตญ์ธํฐ๋ท์งํฅ์์ 10์ผ ์ทจ์ฝ์ ์ฃผ์๋ฅผ ๋น๋ถํ๋ฉฐ ๋ณด์ ๊ณต์งํ๊ณ , Open JS ์ฌ๋จ์ Node.js์์ ๋ฐ์ํ๋ ์ทจ์ฝ์ ์ ํด๊ฒฐํ ๋ณด์ ์ ๋ฐ์ดํธ๋ฅผ ๋ฐํํ๋ค.
Node.js โ Monday, July 8, 2024 Security Releases
Node.jsยฎ is a JavaScript runtime built on Chrome's V8 JavaScript engine.
Node.js โ Monday, July 8, 2024 Security Releases
Node.jsยฎ is a JavaScript runtime built on Chrome's V8 JavaScript engine.