CVE-2019-5413

Updated on 21 Mar 2019

Severity

9.8 Critical severity

Details

CVSS score
9.8
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

Details

Affected product:
Acorn , Express , connect , loopback , morgan , strong-remoting
Affected packages:
connect @ 2.30.2 (+10 more)
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

Fixes