The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-23T00:00:00
Updated: 2024-08-02T21:53:44.706Z
Reserved: 2023-11-23T00:00:00
Link: CVE-2023-49210
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-23T20:15:07.157
Modified: 2024-11-21T08:33:01.917
Link: CVE-2023-49210
Redhat
No data.