CVE-2021-34082 – proctree
Package
Manager: npm
Name: proctree
Vulnerable Version: >=0 <=0.1.1
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:U/RC:C
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: 0.13689 pctl0.93989
Details
OS Command Injection in proctree OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.
Metadata
Created: 2022-06-03T00:00:59Z
Modified: 2022-06-03T22:24:14Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json
CWE IDs: ["CWE-78"]
Alternative ID: GHSA-cv76-rv4h-4mqc
Finding: F404
Auto approve: 1