HIGH
CVE-2021-21315
CVSS
7.8
KEV
Description
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
90.68%
Probability of exploitation in next 30 days
99.8th percentile
References
https://github.com/sebhildebrandt/systeminformation/commit/07daa05fb06f24f96297abaa30c2ace8bfd8b525
Patch
https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v
Third Party Advisory
https://lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715ddf9a4d479b26b05%40%3Cissues.cordova.apache.org%3E
Issue Tracking, Mailing List
https://security.netapp.com/advisory/ntap-20210312-0007/
Third Party Advisory
https://www.npmjs.com/package/systeminformation
Product
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21315
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.