Описание
Command Injection in node-windows
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-45459
- https://github.com/dwisiswant0/advisory/issues/4
- https://github.com/coreybutler/node-windows/commit/a379d31366edbd7a672a981e6c09e185ab448dd3
- https://advisory.dw1.io/4
- https://github.com/coreybutler/node-windows/compare/1.0.0-beta.5...1.0.0-beta.6
- https://security.netapp.com/advisory/ntap-20220107-0004
Пакеты
Наименование
node-windows
npm
Затронутые версииВерсия исправления
<= 1.0.0-beta.5
1.0.0-beta.6
Связанные уязвимости
CVSS3: 9.8
nvd
около 4 лет назад
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.