CVE Feed

    Dashboard / CVE / CVE-2021-21412

    CVE-2021-21412

    Potential for arbitrary code execution in npm package @thi.ng/egf `#gpg`-tagged property values (only if `decrypt: true` option is enabled). PR with patch has been submitted and will has been released as of v0.4.0 By default the EGF parse functions do NOT attempt to decrypt values (since GPG only available in non-browser env). However, if GPG encrypted values are used/required: 1. Perform a regex search for `#gpg`-tagged values in the EGF source file/string and check for backtick (\`) chars in the encrypted value string 2. Replace/remove them or skip parsing if present.

    Published:Mar 30, 2021
    Last Modified:Nov 21, 2024
    EPS:Mar 30, 2021
    EPSS Score:0.01082
    CVSS Score:6.4

    Affected Products

    Vendor
    \@thi.ng\/egf Project
    Product
    \@thi.ng\/egf

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High