PT-2023-12664 · Unknown · Global-Modules-Path

Johns Hopkins

+1

·

Published

2023-01-13

·

Updated

2025-04-04

·

CVE-2022-21191

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions global-modules-path versions prior to 3.0.0
Description The issue is related to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function. This allows for potential exploitation. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 3.0.0, update to version 3.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the getPath function until a patch is available. Restrict access to the getPath function to minimize the risk of exploitation.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-21191
GHSA-VVJ3-85VF-FGMW

Affected Products

Global-Modules-Path