CVE-2020-26245
Summary
| CVE | CVE-2020-26245 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-27 20:15:00 UTC |
| Updated | 2020-12-03 20:12:00 UTC |
| Description | npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite(). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| adapted security update (prototype pollution prevention) · sebhildebrandt/systeminformation@8113ff0 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| command injection vulnerability - prototype pollution · Advisory · sebhildebrandt/systeminformation · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983221 Nodejs (npm) Security Update for systeminformation (GHSA-4v2w-h9jm-mqjg)