Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-652h-xwhf-q4h6

Опубликовано: 21 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

OS Command Injection in ssh2

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

Пакеты

Наименование

ssh2

npm
Затронутые версииВерсия исправления

< 1.4.0

1.4.0

EPSS

Процентиль: 90%
0.05066
Низкий

7.5 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 5.4
redhat
больше 4 лет назад

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

CVSS3: 7.5
nvd
больше 4 лет назад

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

EPSS

Процентиль: 90%
0.05066
Низкий

7.5 High

CVSS3

Дефекты

CWE-78