CVE-2020-36650
Summary
| CVE | CVE-2020-36650 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-11 18:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads to command injection. Upgrading to version 6.0.0 is able to address this issue. The patch is named 5108446c1e23960d65e8b973f1d9486f9f9dbd6c. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218019. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gry Project | Gry | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| huntr.dev - Command Injection Fix by huntr-helper · Pull Request #22 · IonicaBizau/node-gry · GitHub | MISC | github.com | |
| Release 6.0.0 · IonicaBizau/node-gry · GitHub | MISC | github.com | |
| vuldb.com | MISC | vuldb.com | |
| vuldb.com | MISC | vuldb.com | |
| fix command injection vulnerability · IonicaBizau/node-gry@5108446 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.