CVE Vulnerabilities

CVE-2022-21186

Published: Aug 05, 2022 | Modified: Aug 08, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.

Affected Software

Name Vendor Start Version End Version
Filesystem-template Acrontum * 0.0.2 (excluding)

References