Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6q8m-42qq-64r7: Imperative CLI vulnerable to Command Injection

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

ghsa
#vulnerability#nodejs#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2021-4326

Imperative CLI vulnerable to Command Injection

Moderate severity GitHub Reviewed Published Mar 1, 2023 to the GitHub Advisory Database • Updated Mar 1, 2023

Package

npm @zowe/imperative (npm)

Affected versions

< 5.9.0

Description

Published by the National Vulnerability Database

Mar 1, 2023

Published to the GitHub Advisory Database

Mar 1, 2023

Related news

CVE-2021-4326: GitHub - zowe/imperative: Imperative CLI Framework

A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.