Back

CRITICAL

OS Command Injection in ljharb/npm-lockfile

Published Mar 3, 2022

Description

OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.

Affected products

Remediation

Red Hat statement

This flaw only affects npm-lockfile v2. Red Hat Enterprise Linux is not affected by this issue as it ships npm-lockfile v1. Note that the impact is Low as there is no way for external attackers to provide unsafe input and exploit the issue. See huntr vulnerability report (External References) for more information in this regard.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Mar 3, 2022
Updated Aug 2, 2024
Reserved Mar 3, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 3, 2022
ENISA EUVD
Assigner @huntrdev
Published Mar 3, 2022
Updated Aug 2, 2024
Exploited since n/a
EUVD-2022-1409 GHSA-CR6M-62PQ-HMQH