Description
ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1990 | ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0. |
Github GHSA |
GHSA-652h-xwhf-q4h6 | OS Command Injection in ssh2 |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T15:56:04.459Z
Reserved: 2020-10-01T00:00:00.000Z
Link: CVE-2020-26301
No data.
Status : Modified
Published: 2021-09-20T20:15:11.513
Modified: 2024-11-21T05:19:48.493
Link: CVE-2020-26301
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA