PT-2021-16986 · Npm · Node-Config-Shield

CVE-2021-26276

·

Published

2021-01-27

·

Updated

2024-08-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions node-config-shield versions prior to 0.2.2
Description The issue concerns the node-config-shield package, where the scripts/cli.js file calls eval when processing a set command. This could potentially lead to issues if the set command is used with untrusted data. However, the vendor reportedly states that this is not a vulnerability, as the set command was not intended for use with untrusted data.
Recommendations For versions prior to 0.2.2, consider updating to version 0.2.2 or later to mitigate the risk associated with the use of eval when processing the set command. As a temporary workaround, consider restricting the use of the set command to trusted data only until a patch or update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26276
GHSA-W8H4-VW8F-RVVJ

Affected Products

Node-Config-Shield