Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to DLL Injection. An attacker can execute arbitrary code by creating a file with the same name in a folder that precedes the intended file in the DLL path search.
Remediation
Upgrade kerberos
to version 1.0.0 or higher.
References
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- Credit
- Dan Shallom, OP Innovate Ltd
- CVE
- CVE-2020-13110
- CWE
- CWE-114
- Snyk ID
- SNYK-JS-KERBEROS-568900
- Disclosed
- 11 May, 2020
- Published
- 12 May, 2020