CVE-2022-0764
MEDIUM6.1EPSS 0.22%Command injection in strapi
發布日:2022/2/27修改日:2023/11/8
描述
When creating a strapi app using npxcreate-strapi-app, we can inject arbitrary commands through the template cli argument as per the code in this particular [link](https://github.com/strapi/strapi/blob/master/packages/generators/app/lib/utils/fetch-npm-template.js#L13), this happens due to improper sanitization of user input.
受影響套件(1)
- npm/strapifrom 0, < 4.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-0764
- PATCHhttps://github.com/strapi/strapi
- WEBhttps://github.com/strapi/strapi/blob/master/packages/generators/app/lib/utils/fetch-npm-template.js#L13
- WEBhttps://github.com/strapi/strapi/commit/2a3f5e988be6a2c7dae5ac22b9e86d579b462f4c
- WEBhttps://github.com/strapi/strapi/issues/12879
- WEBhttps://huntr.dev/bounties/001d1c29-805a-4035-93bb-71a0e81da3e5
- WEBhttps://www.github.com/strapi/strapi/commit/2a3f5e988be6a2c7dae5ac22b9e86d579b462f4c