Description
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-75w2-qv55-x7fv | openssl npm package vulnerable to command execution |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T21:53:44.706Z
Reserved: 2023-11-23T00:00:00.000Z
Link: CVE-2023-49210
No data.
Status : Modified
Published: 2023-11-23T20:15:07.157
Modified: 2024-11-21T08:33:01.917
Link: CVE-2023-49210
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA