Command Injection in macaddress
Critical severity
GitHub Reviewed
Published
Sep 6, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Sep 6, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
All versions of
macaddress
are vulnerable to command injection. For this vulnerability to be exploited an attacker needs to control theiface
argument to theone
method.Recommendation
Update to version 0.2.9 or later.
References