← Back to CVEs
CVE-2021-34082
CRITICAL9.8
Description
OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published6/2/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
proctree_project:proctree
Weaknesses (CWE)
CWE-78
References
https://advisory.checkmarx.net/advisory/CX-2021-4783(cve@mitre.org)
https://advisory.checkmarx.net/advisory/CX-2021-4783(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/allenhwkim/proctree/blob/master/index.js#L46(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.