Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m57p-p67h-mq74

Опубликовано: 16 дек. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

Command Injection Vulnerability in systeminformation

Impact

command injection vulnerability

Patches

Problem was fixed with a shell string sanitation fix. Please upgrade to version >= 4.31.1

Workarounds

If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetLatency()

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

systeminformation

npm
Затронутые версииВерсия исправления

< 4.31.1

4.31.1

EPSS

Процентиль: 80%
0.01389
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 6.4
nvd
около 5 лет назад

In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.

EPSS

Процентиль: 80%
0.01389
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-78