VDB
BDU%3A2021-05431
BDU%3A2021-05431
PUBLISHED
CVSS 10 CRITICAL
Уязвимость библиотеки systeminformation программной платформы Node.js, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Node.js Foundation, IBM Corp. | Node.js, IBM Spectrum Protect Plus |
Timeline
- Nov 12, 2021 CVE Published
References
- https://github.com/sebhildebrandt/systeminformation/commit/7922366d707de7f20995fc8e30ac3153636bf35f url
- https://github.com/sebhildebrandt/systeminformation/commit/0be6fcd575c05687d1076d5cd6d75af2ebae5a46 url
- https://github.com/sebhildebrandt/systeminformation/commit/01ef56cd5824ed6da1c11b37013a027fdef67524 url
- https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-jff2-qjw8-5476 url
- https://www.npmjs.com/package/systeminformation url
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-apache-commons-and-node-js-affect-ibm-spectrum-protect-plus/ advisory