OSV 1.4.0 · github-reviewed · 修改于 2021-09-17 03:31
发布时间
2019-02-19 07:39
GitHub 审查时间
2020-06-17 05:51
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/02/GHSA-q52j-4q2q-hcj6/GHSA-q52j-4q2q-hcj6.json
Affected versions of the console-io package do not configure the underlying websocket library to require authentication, resulting in an authentication bypass vulnerability. As console-io allows terminal access on the server via a web page, an authentication bypass is essentially remote code execution.
Update to version 2.3.0 or later.