Junglewise Threat Intelligence

CVE-2020-7624: effect OS command injection (withdrawn)

CVE-2020-7624 · Severity: critical · CVSS 9.8 · Published 2022-02-10

Vendors: npm.

Executive brief

This advisory has been withdrawn. The npm package "effect" (a Node.js image effect library) was claimed to have a command injection vulnerability, but the advisory was withdrawn because the npm package does not match the vulnerable GitHub repository, and the CVE issuer has since stated this was not actually a vulnerability.

Technical details

The original advisory alleged that the "effect" npm package through version 1.0.4 was vulnerable to OS command injection (CWE-78) via unsanitized user input in the options parameter. However, the advisory was withdrawn on June 4, 2024, for two critical reasons: (1) the npm package "effect" does not correspond to the vulnerable GitHub repository (https://github.com/Javascipt/effect), which is not in a supported ecosystem, and (2) the CVE Numbering Authority that issued CVE-2020-7624 has updated their advisory stating that "This was deemed not a vulnerability." As such, this is not an actionable security issue.

Affected products

  • npm effect <= 1.0.4

Timeline

  • 2020-04-02: disclosed
  • 2022-02-10: advisory: Added to GitHub Advisory Database
  • 2024-06-04: other: Advisory withdrawn; CVE issuer deemed not a vulnerability

References

Related threats