CVE-2017-16024

The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:sync-exec_project:sync-exec:*:*:*:*:*:node.js:*:*

Configuration 2 (hide)

cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-06-04 19:29

Updated : 2024-02-04 19:46


NVD link : CVE-2017-16024

Mitre link : CVE-2017-16024

CVE.ORG link : CVE-2017-16024


JSON object : View

Products Affected

nodejs

  • node.js

sync-exec_project

  • sync-exec
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-377

Insecure Temporary File