vendor:
serialize
by:
Beren Kuday GORUN
9,8
CVSS
HIGH
Remote Code Execution
95
CWE
Product Name: serialize
Affected Version From: 0.0.4
Affected Version To: 0.0.4
Patch Exists: YES
Related CWE: 2017-5941
CPE: a:luin:serialize
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows & Ubuntu
2021
Node.JS – ‘node-serialize’ Remote Code Execution (3)
A vulnerability in the node-serialize module of Node.js could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to improper validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized payload to the targeted system. A successful exploit could allow the attacker to execute arbitrary code on the targeted system.
Mitigation:
Upgrade to the latest version of node-serialize module of Node.js.