Описание
ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.
Ссылки
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- ProductThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Одновременно
EPSS
7.5 High
CVSS3
10 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.
EPSS
7.5 High
CVSS3
10 Critical
CVSS3
7.5 High
CVSS2