Security Advisory

CVE-2019-10791

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-02-18 16:01:20
Last updated 2024-08-04 22:32:02
Assigner snyk
CVSS score not scored
State PUBLISHED

Description

promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.