HIGH 8.9 npm
Command Injection Vulnerability in systeminformation
GHSA-jff2-qjw8-5476 · CVE-2021-21388
Published · Modified
Description
Impact
command injection vulnerability
Patches
Problem was fixed with a parameter check. Please upgrade to version >= 5.6.4
Workarounds
If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
References
- WEB https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-jff2-qjw8-5476
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-21388
- WEB https://github.com/sebhildebrandt/systeminformation/commit/01ef56cd5824ed6da1c11b37013a027fdef67524
- WEB https://github.com/sebhildebrandt/systeminformation/commit/0be6fcd575c05687d1076d5cd6d75af2ebae5a46
- WEB https://github.com/sebhildebrandt/systeminformation/commit/7922366d707de7f20995fc8e30ac3153636bf35f
- WEB https://www.npmjs.com/package/systeminformation
Ready to move
Start Securing
Free, no credit card | First findings in minutes