Количество 2
Количество 2
CVE-2021-34083
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE.
GHSA-7xhv-mpjw-422f
Command injection in google-it
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-34083 Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-7xhv-mpjw-422f Command injection in google-it | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу