Rewterz Threat Alert – APT-C-35 aka Donot APT Group – Active IOCs
February 22, 2023Rewterz Threat Alert – BumbleBee Malware – Active IOCs
February 22, 2023Rewterz Threat Alert – APT-C-35 aka Donot APT Group – Active IOCs
February 22, 2023Rewterz Threat Alert – BumbleBee Malware – Active IOCs
February 22, 2023Severity
High
Analysis Summary
CVE-2023-25805
Node.js versionn module could allow a remote attacker to execute arbitrary commands on the system, caused by a command injection flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Impact
- Command Execution
Indicators Of Compromise
CVE
- CVE-2023-25805
Affected Vendors
Node.js
Affected Products
- Node.js versionn 1.0.6
Remediation
Upgrade to the latest version of versionn, available from the versionn GIT Repository.