PT-2021-18165 · Unknown · @Ronomon/Opened
Fábio Freitas
·
Published
2021-05-24
·
Updated
2021-06-08
·
CVE-2021-29300
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
@ronomon/opened versions prior to 1.5.2
Description:
The issue allows a remote attacker to execute commands on the system if the library is used with untrusted input. This is a command injection vulnerability.
Recommendations:
For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all input to prevent command injection attacks. Restrict access to the library when handling untrusted input to minimize the risk of exploitation.
Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Ronomon/Opened