Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-94xh-2fmc-xf5j

Опубликовано: 27 окт. 2020
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

systeminformation command injection vulnerability

Impact

command injection vulnerability

Patches

Problem was fixed with a shell string sanitation fix. Please upgrade to version >= 4.27.11

Workarounds

If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite()

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

systeminformation

npm
Затронутые версииВерсия исправления

< 4.27.11

4.27.11

EPSS

Процентиль: 87%
0.03143
Низкий

8.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

EPSS

Процентиль: 87%
0.03143
Низкий

8.8 High

CVSS3

Дефекты

CWE-78