The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows...
Vulnerability Description
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-21268
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.linkedin.com/posts/op-innovate_shell-command-injection-through-traceroute-activity-6678956453086191616-Rcpy
- https://www.op-c.net/2020/06/17/shell-command-injection-through-traceroute-npm-package/
- https://medium.com/%40shay_62828/shell-command-injection-through-traceroute-npm-package-a4cf7b6553e3
- https://github.com/jaw187/node-traceroute/tags
- https://www.npmjs.com/package/traceroute
- https://www.npmjs.com/advisories/1465
- https://snyk.io/vuln/npm:traceroute:20160311
- https://github.com/jaw187/node-traceroute/commit/b99ee024a01a40d3d20a92ad3769cc78a3f6386f
Affected Vendor
traceroute project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.