Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj59-f6c3-3vw4

Опубликовано: 27 окт. 2020
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Command Injection in systeminformation

Impact

command injection vulnerability

Patches

Problem was fixed with a shell string sanitation fix. Please upgrade to version >= 4.26.2

Workarounds

If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to is.services(), is.inetChecksite(), si.inetLatency(), si.networkStats(), is.services() and si.processLoad()

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

systeminformation

npm
Затронутые версииВерсия исправления

< 4.26.2

4.26.2

EPSS

Процентиль: 78%
0.01121
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 5.9
nvd
больше 4 лет назад

systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.

EPSS

Процентиль: 78%
0.01121
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-78