9.8

CVE-2022-21165

Exploit

Arbitrary Command Injection

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Font Converter Project ≫ Font Converter Version 1.0.0 SwPlatform node.js
Font Converter Project ≫ Font Converter Version 1.1.0 SwPlatform node.js
Font Converter Project ≫ Font Converter Version 1.1.1 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.05% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Snyk 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/zgec/node-js-font-converter/blob/master/index.js%23L12
Third Party Advisory
Broken Link
https://security.snyk.io/vuln/SNYK-JS-FONTCONVERTER-2976194
Third Party Advisory
Exploit