CVE-2024-36138

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2024-36138
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-36138.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-36138
Aliases
Related
Published
2024-09-07T16:15:02Z
Modified
2024-09-10T07:57:44.932460Z
Summary
[none]
Details

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via childprocess.spawn / childprocess.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

References

Affected packages

Alpine:v3.19 / nodejs

Package

Name
nodejs
Purl
pkg:apk/alpine/nodejs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0

Alpine:v3.20 / nodejs

Package

Name
nodejs
Purl
pkg:apk/alpine/nodejs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0