Fedora Account System
Red Hat Associate
Red Hat Customer
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
Upstream commit: https://github.com/scravy/node-macaddress/commit/358fd594adb196a86b94ac9c691f69fe5dad2332
Statement: Red Hat Quay uses the macaddress module, but only as a development dependency, not at runtime reducing the impact on that product to low.