Node.js.Debugger.Remote.Command.Injection

description-logoDescription

This indicates an attack attempt to exploit a Command Injection Vulnerability in NodeJS.
The vulnerability is due to an input validation error while parsing a crafted request to a specific port. A remote attacker could exploit this to execute arbitrary code within the context of the target application, via sending a crafted request to specific port.

affected-products-logoAffected Products

NodeJS

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor. Or follow the workaround in below link.
https://github.com/nodejs/node/pull/8106

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-09-29 16.933 Name:NodeJS.
Debugger.
Remote.
Command.
Injection:Node.
js.
Debugger.
Remote.
Command.
Injection

References

8106