Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c3f-x5f9-6h62

Опубликовано: 02 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 3.9

Описание

Command injection in @diez/generation

The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. All versions of this package are vulnerable as of the writing of this CVE.

Пакеты

Наименование

@diez/generation

npm
Затронутые версииВерсия исправления

<= 10.6.0

Отсутствует

EPSS

Процентиль: 42%
0.002
Низкий

3.9 Low

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 3.9
nvd
больше 4 лет назад

The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. All versions of this package are vulnerable as of the writing of this CVE.

EPSS

Процентиль: 42%
0.002
Низкий

3.9 Low

CVSS3

Дефекты

CWE-77
CWE-78