CVE-2019-5413

Updated on 21 Mar 2019

Severity

9.8 Critical severity

Details

CVSS score
9.8
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

Details

Affected product:
Acorn , Express , connect , morgan
Affected packages:
express @ 3.21.2 (+7 more)
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

Fixes