We found results for “”
WS-2021-0630
Good to know:
Date: September 13, 2021
There is "OS Command Injection" vulnerability on "is-program-installed" npm package before 2.3.4. This package tries to understand the given parameter name (program or binary name) is installed in the computer or not. However, since this package does not properly control the characters in the program name taken as input, it is possible to run commands on the operating system.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
OS Command Injections
CWE-78Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |