CVE-2020-13110
16.05.2020, 12:15
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.Enginsight
Vendor | Product | Version |
---|---|---|
kerberos_project | kerberos | 𝑥 < 1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References