CVE-2020-26300
Summary
| CVE | CVE-2020-26300 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-09 01:15:00 UTC |
| Updated | 2022-04-26 15:33:00 UTC |
| Description | systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Command Injection · GHSA-fj59-f6c3-3vw4 · GitHub Advisory Database · GitHub |
CONFIRM |
github.com |
|
| systeminformation - npm |
MISC |
www.npmjs.com |
|
| improved shell sanitation · sebhildebrandt/systeminformation@bad372e · GitHub |
MISC |
github.com |
|
| command injection vularibiliry · Advisory · sebhildebrandt/systeminformation · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981112 Nodejs (npm) Security Update for systeminformation (GHSA-fj59-f6c3-3vw4)