SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7789

It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.

MEDIUM 5.6EPSS 1.59%

Does this matter?

Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.

Description

This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
1.59% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
node-notifier project/node-notifier
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.