CVE-2024-36138
07.09.2024, 16:15
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
Vendor | Product | Version |
---|---|---|
nodejs | nodejs | 18.20.4 < 𝑥 < 18.20.4 |
nodejs | nodejs | 20.15.1 < 𝑥 < 20.15.1 |
nodejs | nodejs | 22.4.1 < 𝑥 < 22.4.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases