CVE-2021-26276
/
CX-2021-4773
Advisories
Disclosure Policy
Contact Us
Check with SCA
Defend your code against
SpringShell
in two ways: read our
blog post
with what-to-do advice, and use
Checkmarx SCA
to test your applications.
5.3
Medium
Severity
Medium Severity
5.3
CVE-2021-26276
/
CX-2021-4773
/ State: Published
Command injection vulnerability in the config-shield NPM package
node
nodejs
javascript
npm
rce
typescript
Adar Zandberg
Jan 21, 2021
Details
Overview
5.3
Medium
Severity
Medium Severity
5.3
Properties
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Confidentiality:
None
Integrity:
Low
Availability:
None
Advisory Timeline
Discovered
Jan 20, 2021
Fixed
Jan 21, 2021
Published
Jan 21, 2021
Stay up to date with our newsletter
Subscribe
/advisory/CX-2021-4773/