PT-2021-16986 · Npm · Node-Config-Shield
CVE-2021-26276
·
Published
2021-01-27
·
Updated
2024-08-03
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
node-config-shield versions prior to 0.2.2
Description
The issue concerns the node-config-shield package, where the
scripts/cli.js file calls eval when processing a set command. This could potentially lead to issues if the set command is used with untrusted data. However, the vendor reportedly states that this is not a vulnerability, as the set command was not intended for use with untrusted data.Recommendations
For versions prior to 0.2.2, consider updating to version 0.2.2 or later to mitigate the risk associated with the use of
eval when processing the set command. As a temporary workaround, consider restricting the use of the set command to trusted data only until a patch or update is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node-Config-Shield