OS Command Injection in ljharb/npm-lockfile
Published Mar 3, 2022
9.8
CRITICALCVSS 3.1
EPSS 2.51%
Description
OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
Affected products
-
- Version 2.0.3StatusaffectedConstraints-
- Version 2.0.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Ljharb | Ljharb/npm-Lockfile | n/a |
|
- 2.0.3
- 2.0.4
No data.
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Not affected
Red Hat Enterprise Linux 8
cockpit
Not affected
Red Hat Enterprise Linux 8
cockpit-appstream
Not affected
Red Hat Enterprise Linux 8
container-tools:2.0/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
container-tools:rhel8/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
nodejs:12/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
Red Hat Software Collections
rh-nodejs12-nodejs
Not affected
Red Hat Software Collections
rh-nodejs14-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-appstream | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:2.0/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:12/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs12-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Not affected | n/a |
npm-lockfile
npm
Introduced 2.0.3 Fixed 2.0.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | npm-lockfile | 2.0.3 | 2.0.5 |
Remediation
Red Hat statement
This flaw only affects npm-lockfile v2. Red Hat Enterprise Linux is not affected by this issue as it ships npm-lockfile v1. Note that the impact is Low as there is no way for external attackers to provide unsafe input and exploit the issue. See huntr vulnerability report (External References) for more information in this regard.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-0841 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060615 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1409 Advisory
- https://github.com/advisories/GHSA-cr6m-62pq-hmqh Advisory
- https://github.com/ljharb/npm-lockfile/commit/bfdb84813260f0edbf759f2fde1e8c816c1478b8 x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/4f806dc9-2ecd-4e79-997e-5292f1bea9f1 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0841
- https://www.cve.org/CVERecord?id=CVE-2022-0841
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0841 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2060615 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1409 | Advisory | |
| https://github.com/advisories/GHSA-cr6m-62pq-hmqh | Advisory | |
| https://github.com/ljharb/npm-lockfile/commit/bfdb84813260f0edbf759f2fde1e8c816c1478b8 | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/4f806dc9-2ecd-4e79-997e-5292f1bea9f1 | x_refsource_CONFIRMExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0841 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0841 |
Change history (0)
No recorded changes yet.