Remote command execution In payload
Description
Payload: Remote Code Execution through first-register
Impact
A crafted request to the public first-register operation can be used to perform a RCE exploit.
You are affected if:
You use local auth strategy and your application remains without an initial user created
Patches
In the patched version data submission to create first user is properly sanitized.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.