Executive brief
kill-port is a Node.js utility used to forcefully terminate processes running on specified network ports. Versions before 1.3.2 fail to validate user input when killing processes, allowing an attacker to inject arbitrary shell commands that execute with the privileges of the process running kill-port. An exploit could lead to complete system compromise if the application is exposed to untrusted input.
Technical details
The vulnerability is a command injection flaw (CWE-77) in the kill function of kill-port prior to version 1.3.2. The root cause is insufficient input validation on the port parameter passed to the kill function. An attacker who can supply a malicious port number (e.g., through an API or user input) can inject shell metacharacters to execute arbitrary commands on the system. The attack vector is network-accessible if the application exposing kill-port is network-reachable; no authentication is required. An attacker gains arbitrary code execution in the context of the running process. The vulnerability was fixed in version 1.3.2.
Affected products
- kill-port kill-port prior to 1.3.2
Timeline
- 2019-03-25: disclosed
- 2019: patched: version 1.3.2