CVE-2014-9682 describes a critical command injection vulnerability in the dns-sync module for Node.js, affecting versions prior to 0.1.1. Attackers can achieve arbitrary command execution by injecting shell metacharacters into the first argument of the resolve API function. This vulnerability carries a CVSS score of 10.0, indicating a severe risk with network-based attacks, low complexity, and complete compromise of confidentiality, integrity, and availability. While no known public exploits like Metasploit or Nuclei exist, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.1.0CPE matchmatch criteria | cpe:2.3:a:dns-sync_project:dns-sync:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.