Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5mw-f2hq-5fw8

Опубликовано: 11 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

gry vulnerable to Command Injection

A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads to command injection. Upgrading to version 6.0.0 is able to address this issue. The name of the patch is 5108446c1e23960d65e8b973f1d9486f9f9dbd6c. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218019.

Пакеты

Наименование

gry

npm
Затронутые версииВерсия исправления

< 6.0.0

6.0.0

EPSS

Процентиль: 71%
0.0067
Низкий

8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 5.5
nvd
около 3 лет назад

A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads to command injection. Upgrading to version 6.0.0 is able to address this issue. The patch is named 5108446c1e23960d65e8b973f1d9486f9f9dbd6c. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218019.

EPSS

Процентиль: 71%
0.0067
Низкий

8 High

CVSS3

Дефекты

CWE-77