Security Advisory

CVE-2022-29080

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-04-12 04:45:34
Last updated 2024-08-03 06:10:59
Assigner mitre
State PUBLISHED

Description

The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.