Junglewise Threat Intelligence

CVE-2020-7697: mock2easy code injection vulnerability

CVE-2020-7697 · Severity: low · CVSS 3.1 · Published 2021-05-06

Vendors: npm.

Executive brief

mock2easy is a Node.js library used to mock API interfaces for testing purposes. A vulnerability allows attackers to inject malicious commands through user-controlled input, potentially leading to arbitrary code execution on servers running the library.

Technical details

This is a command injection vulnerability (CWE-77) affecting mock2easy versions up to 0.0.24. The vulnerability exists in the route handler where user-supplied data from the _data variable (specifically interfaceUrl, cookie, and interfaceType parameters) is passed unsanitized to a child process execution function. An attacker with network access can craft malicious input containing shell metacharacters or commands that will be executed by the system. The vulnerability requires no authentication and no user interaction beyond sending a crafted HTTP request. A patch or upgrade to a version after 0.0.24 is required to remediate this issue.

Affected products

  • mock2easy mock2easy <=0.0.24

Timeline

  • 2020-07-29: disclosed
  • 2021-05-06: advisory

References