Command Injection in Node.js - CVE-2024-36138
Published: July 9, 2024
Node.js
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
IBM Business Automation Workflow
EasyApache
IBM Cloud Transformation Advisor
IBM Spectrum Control
IBM Cloud Pak for Business Automation
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Oracle GraalVM for JDK
Planning Analytics Local
IBM Cognos Controller
IBM InfoSphere Information Server
nodejs18-debugsource
nodejs18-devel
nodejs18-docs
nodejs18-debuginfo
nodejs18
npm18
corepack18
nodejs20-debugsource
nodejs20-docs
nodejs20-devel
npm20
nodejs20-debuginfo
nodejs20
corepack20
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper handling of batch files in child_process.spawn / child_process.spawnSync on Windows. An attacker can inject a malicious command line argument and achieve code execution even if the shell option is not enabled.
Note, the vulnerability exists due to incomplete fix for #VU88462 (CVE-2024-27980).