Critical severity9.8NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2021-34080
CVE-2021-34080
Description
OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ssl-utilsnpm | <= 1.0.0 | — |
Affected products
3- cpe:2.3:a:ssl-utils_project:ssl-utils:*:*:*:*:*:node.js:*:*Range: <=1.0.0
- es128/ssl-utilsdescription
Patches
Vulnerability mechanics
References
3- advisory.checkmarx.net/advisory/CX-2021-4782nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-552j-pv39-f3jfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-34080ghsaADVISORY
News mentions
0No linked articles in our index yet.