CVE-2019-5414

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/03/2019
Last modified:
09/10/2019

Description

If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kill-port_project:kill-port:*:*:*:*:*:node.js:*:* 1.3.2 (excluding)


References to Advisories, Solutions, and Tools