docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://snyk.io/vuln/SNYK-JS-DOCKERCOMPOSEREMOTEAPI-560125 |
|
History
No history.
Status: PUBLISHED
Assigner: snyk
Published: 2020-03-15T21:31:11
Updated: 2024-08-04T09:33:19.966Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7606
No data.
Status : Modified
Published: 2020-03-15T22:15:14.880
Modified: 2024-11-21T05:37:27.763
Link: CVE-2020-7606
No data.