Deno is Vulnerable to Command Injection on Windows During Batch File Execution
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.1epss 2.1%
probabilidad de explotación
2.1%top 20% de las CVE
explotación observada
noninguna fuente lo reporta
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
denoland · denoReferencias
https://github.com/denoland/deno/commit/8a0990ccd37bafd8768176ca64b906ba2da2d822https://github.com/denoland/deno/pull/30818https://github.com/denoland/deno/releases/tag/v2.2.15https://github.com/denoland/deno/releases/tag/v2.5.3https://github.com/denoland/deno/security/advisories/GHSA-m2gf-x3f6-8hq3