CRITICAL
Arbitrary Command Injection
Published Aug 5, 2022
9.8
CRITICALCVSS 3.1
EPSS 25.40%
Description
The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
Affected products
No data.
- < 0.0.2
No data.
No Red Hat product state for this CVE.
@acrontum/filesystem-template
npm
Introduced 0 Fixed 0.0.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @acrontum/filesystem-template | 0 | 0.0.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/acrontum/filesystem-template/commit/baeb727b60991ad82d9e63ac660883793abc0acc
- https://github.com/acrontum/filesystem-template/issues/13
- https://github.com/acrontum/filesystem-template/pull/14/commits/baeb727b60991ad82d9e63ac660883793abc0acc x_refsource_MISCPatchThird Party Advisory
- https://github.com/advisories/GHSA-m2fc-9h5m-29cm Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-21186
- https://security.snyk.io/vuln/SNYK-JS-ACRONTUMFILESYSTEMTEMPLATE-2419071 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/acrontum/filesystem-template/commit/baeb727b60991ad82d9e63ac660883793abc0acc | ||
| https://github.com/acrontum/filesystem-template/issues/13 | ||
| https://github.com/acrontum/filesystem-template/pull/14/commits/baeb727b60991ad82d9e63ac660883793abc0acc | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-m2fc-9h5m-29cm | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-21186 | ||
| https://security.snyk.io/vuln/SNYK-JS-ACRONTUMFILESYSTEMTEMPLATE-2419071 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Aug 5, 2022
Updated Sep 16, 2024
Reserved Feb 24, 2022
Link CVE-2022-21186
CISA Vulnrichment
GHSA-M2FC-9H5M-29CM Updated n/a