Critical severityNVD Advisory· Published Dec 22, 2021· Updated Aug 4, 2024
CVE-2021-45459
CVE-2021-45459
Description
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
node-windowsnpm | < 1.0.0-beta.6 | 1.0.0-beta.6 |
Affected products
2- node-windows/node-windowsdescription
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-53xv-c2hx-5w6qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-45459ghsaADVISORY
- advisory.dw1.io/4ghsaWEB
- github.com/coreybutler/node-windows/commit/a379d31366edbd7a672a981e6c09e185ab448dd3ghsaWEB
- github.com/coreybutler/node-windows/compare/1.0.0-beta.5...1.0.0-beta.6ghsax_refsource_MISCWEB
- github.com/dwisiswant0/advisory/issues/4ghsax_refsource_MISCWEB
- security.netapp.com/advisory/ntap-20220107-0004ghsaWEB
- security.netapp.com/advisory/ntap-20220107-0004/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.