Publish GHSA-2m8v-572m-ff2v

This commit is contained in:
advisory-database[bot]
2024-07-25 15:02:15 +00:00
parent 3702e7c6a3
commit 3aec85f3d9
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2m8v-572m-ff2v",
"modified": "2021-02-16T16:50:49Z",
"modified": "2024-07-25T15:00:42Z",
"published": "2021-02-16T16:51:04Z",
"aliases": [
"CVE-2021-21315"
@@ -9,7 +9,10 @@
"summary": "Command Injection Vulnerability",
"details": "### Impact\ncommand injection vulnerability\n\n### Patches\nProblem was fixed with a parameter check. Please upgrade to version >= 5.3.1\n\n### Workarounds\nIf you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
@@ -45,6 +48,10 @@
"type": "WEB",
"url": "https://github.com/sebhildebrandt/systeminformation/commit/07daa05fb06f24f96297abaa30c2ace8bfd8b525"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715ddf9a4d479b26b05%40%3Cissues.cordova.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715ddf9a4d479b26b05@%3Cissues.cordova.apache.org%3E"
@@ -62,7 +69,7 @@
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2021-02-16T16:50:49Z",
"nvd_published_at": "2021-02-16T17:15:00Z"