PT-2021-18165 · Unknown · @Ronomon/Opened

Fábio Freitas

·

Published

2021-05-24

·

Updated

2021-06-08

·

CVE-2021-29300

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: @ronomon/opened versions prior to 1.5.2
Description: The issue allows a remote attacker to execute commands on the system if the library is used with untrusted input. This is a command injection vulnerability.
Recommendations: For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all input to prevent command injection attacks. Restrict access to the library when handling untrusted input to minimize the risk of exploitation.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29300
GHSA-FG5W-W99F-RJ6W

Affected Products

@Ronomon/Opened