CVE-2020-26274

MEDIUM6.4EPSS 1.4%

Command Injection Vulnerability in systeminformation

發布日:2020/12/16修改日:2026/3/13
也稱為:GHSA-m57p-p67h-mq74DEBIAN-CVE-2020-26274

描述

### Impact command injection vulnerability ### Patches Problem was fixed with a shell string sanitation fix. Please upgrade to version >= 4.31.1 ### Workarounds If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetLatency() ### For more information If you have any questions or comments about this advisory: * Open an issue in [systeminformation](https://github.com/sebhildebrandt/systeminformation/issues/new?template=bug_report.md)

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

參考連結(6)