VYPR

Docker Compose Remote API

by Docker Compose Remote API Project

CVEs (1)

  • CVE-2020-7606CriMar 15, 2020
    risk 0.64cvss 9.8epss 0.03

    docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.