Intrusion Prevention

NodeJS.Debugger.Remote.Command.Injection

Description

This indicates an attack attempt to exploit a Command Injection Vulnerability in NodeJS.
The vulnerability is due to an input validation error while parsing a crafted request to a specific port. A remote attacker could exploit this to execute arbitrary code within the context of the target application, via sending a crafted request to specific port.

Affected Products

NodeJS

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor. Or follow the workaround in below link.
https://github.com/nodejs/node/pull/8106

Other References

8106