{"id":"GHSA-wxvm-fh75-mpgr","summary":"Critical severity vulnerability that affects dns-sync","details":"Withdrawn, accidental duplicate publish.\n\nThe dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.","modified":"2020-06-17T15:15:19Z","published":"2018-07-26T16:24:34Z","withdrawn":"2020-06-17T15:15:19Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-17T15:15:19Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9682"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wxvm-fh75-mpgr"}],"affected":[{"package":{"name":"dns-sync","ecosystem":"npm","purl":"pkg:npm/dns-sync"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-wxvm-fh75-mpgr/GHSA-wxvm-fh75-mpgr.json"}}],"schema_version":"1.9.0"}