Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21315

Опубликовано: 16 фев. 2021
Источник: debian
EPSS Критический

Описание

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-systeminformationnot-affectedpackage

EPSS

Процентиль: 100%
0.9024
Критический

Связанные уязвимости

CVSS3: 7.1
nvd
больше 5 лет назад

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

CVSS3: 7.8
github
больше 5 лет назад

Command Injection Vulnerability

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость пакета npm systeminformation программной платформы Node.js, позволяющая нарушителю выполнить произвольную команду

EPSS

Процентиль: 100%
0.9024
Критический