logo

CVE-2021-34082 proctree

Package

Manager: npm
Name: proctree
Vulnerable Version: >=0 <=0.1.1

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:U/RC:C

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

EPSS: 0.13689 pctl0.93989

Details

OS Command Injection in proctree OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.

Metadata

Created: 2022-06-03T00:00:59Z
Modified: 2022-06-03T22:24:14Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json
CWE IDs: ["CWE-78"]
Alternative ID: GHSA-cv76-rv4h-4mqc
Finding: F404
Auto approve: 1