logo

CVE-2022-41642 nadesiko3

Package

Manager: npm
Name: nadesiko3
Vulnerable Version: >=0 <3.3.69

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

EPSS: 0.0087 pctl0.74327

Details

Nadesiko3 OS Command Injection vulnerability OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.68 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product. Release notes for versions 3.3.62 and 3.3.69 both link to patches for this particular issue. The [JPCERT/CC](https://jvn.jp/en/jp/JVN56968681/index.html) advisory lists versions 3.3.68 and prior as vulnerable, and the most recent patch for this issue is tagged with version 3.3.69.

Metadata

Created: 2022-12-05T06:30:22Z
Modified: 2022-12-06T22:26:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-m8r5-7wf4-63mw/GHSA-m8r5-7wf4-63mw.json
CWE IDs: ["CWE-78"]
Alternative ID: GHSA-m8r5-7wf4-63mw
Finding: F404
Auto approve: 1