CVE-2022-29080

The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.
References
Configurations

Configuration 1

cpe:2.3:a:npm-dependency-versions_project:npm-dependency-versions:*:*:*:*:*:node.js:*:*

Information

Published : 2022-04-12 05:15

Updated : 2022-04-19 03:51


NVD link : CVE-2022-29080

Mitre link : CVE-2022-29080

Products Affected
No products.
CWE