Junglewise Threat Intelligence

CVE-2021-23360: killport command injection via unsanitized port parameter

CVE-2021-23360 · Severity: low · CVSS 3.1 · Published 2021-04-13

Vendors: npm.

Executive brief

killport is a utility that terminates processes listening on a specified network port. A command injection vulnerability allows an attacker to execute arbitrary system commands by providing a malicious port number, potentially compromising the system running the tool and enabling unauthorized code execution.

Technical details

This is a command injection vulnerability (CWE-77) in the killport npm package. The vulnerable code uses Node.js child_process.exec() to run an lsof command with an unsanitized user-supplied port parameter, allowing an attacker to inject shell metacharacters and execute arbitrary commands. The vulnerability requires local access or the ability to supply input to the killport function; an attacker can craft a malicious port string (e.g., containing shell operators like `;` or `|`) to break out of the intended lsof command. The fix, released in version 1.0.2, adds input validation using a regular expression to ensure the port parameter contains only digits before passing it to exec().

Affected products

  • killport killport before 1.0.2

Timeline

  • 2021-04-13: disclosed: GitHub Security Advisory published
  • 2021: patched: Fixed in version 1.0.2

References