CVE-2021-21315
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- System Information Library for Node.JS Command Injection
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 90% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-78
מוצרים מושפעים
systeminformation: systeminformation; apache: cordova
קישורים
- https://github.com/sebhildebrandt/systeminformation/commit/07daa05fb06f24f9629… Patch
- https://github.com/sebhildebrandt/systeminformation/commit/07daa05fb06f24f9629… Patch
- https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2… Third Party Advisory
- https://lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715… Issue TrackingMailing List
- https://security.netapp.com/advisory/ntap-20210312-0007/ Third Party Advisory
- https://www.npmjs.com/package/systeminformation Product
- https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2… Third Party Advisory
- https://lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715… Issue TrackingMailing List
- https://security.netapp.com/advisory/ntap-20210312-0007/ Third Party Advisory
- https://www.npmjs.com/package/systeminformation Product