DEBIAN-CVE-2021-21388
Dashboard / Vulnerabilities / DEBIAN-CVE-2021-21388
Summary:
Details: systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a parameter check on user input. Please upgrade to version >= 5.6.4. If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() and other commands. Only allow strings, reject any arrays. String sanitation works as expected.
Affected packages
Package
Name: node-systeminformation
Purl: pkg:deb/debian/node-systeminformation?arch=source&distro=forky
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
5.31.6-1
5.31.6-2
5.31.6-3
5.31.6-4
5.31.7-1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
