Rewterz Threat Advisory – CVE-2021-23001 – F5 BIG-IP (Advanced WAF, ASM) security bypass
April 1, 2021Rewterz Threat Alert – Russian APT Gamaredon Using Template Injection
April 1, 2021Rewterz Threat Advisory – CVE-2021-23001 – F5 BIG-IP (Advanced WAF, ASM) security bypass
April 1, 2021Rewterz Threat Alert – Russian APT Gamaredon Using Template Injection
April 1, 2021Severity
Medium
Analysis Summary
CVE-2021-23348
Node.js portprocesses module could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by improper input validation by the killProcess function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Impact
Gain access
Affected Vendors
NodeJs
Affected Products
- Node.js portprocesses 1.0.4
- Node.js portprocesses 1.0.3
Remediation
Upgrade to the latest version of portprocesses (1.0.5 or later)