Логотип exploitDog
bind:CVE-2022-29256
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29256

Количество 2

Количество 2

nvd логотип

CVE-2022-29256

больше 3 лет назад

sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of the `PKG_CONFIG_PATH` environment variable in a build environment then they might be able to use this to inject an arbitrary command at `npm install` time. This is not part of any runtime code, does not affect Windows users at all, and is unlikely to affect anyone that already cares about the security of their build environment. This problem is fixed in version 0.30.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gp95-ppv5-3jc5

больше 3 лет назад

sharp vulnerable to Command Injection in post-installation over build environment

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-29256

sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of the `PKG_CONFIG_PATH` environment variable in a build environment then they might be able to use this to inject an arbitrary command at `npm install` time. This is not part of any runtime code, does not affect Windows users at all, and is unlikely to affect anyone that already cares about the security of their build environment. This problem is fixed in version 0.30.5.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gp95-ppv5-3jc5

sharp vulnerable to Command Injection in post-installation over build environment

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу