Bug 2166721 (CVE-2022-21191)

Summary: CVE-2022-21191 global-modules-path: Command Injection due to missing Input Sanitization
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: alampare, alazarot, dhanak, emingora, gjospin, ibek, jrokos, kverlaen, lbacciot, mnovotny, pjindal, rguimara, rrajasek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: global-modules-path 3.0.0 Doc Type: ---
Doc Text:
A flaw was found in global-modules-path. This issue may allow command injection via getPath due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-02-08 15:31:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2161211    

Description Patrick Del Bello 2023-02-02 18:12:38 UTC
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

https://github.com/lorenzomigliorero/npm-node-utils/blob/b55dd81c597db657c9751332bb2242403fd3e26b/index.js%23L186
https://security.snyk.io/vuln/SNYK-JS-GLOBALMODULESPATH-3167973
https://github.com/rosen-vladimirov/global-modules-path/releases/tag/v3.0.0
https://github.com/rosen-vladimirov/global-modules-path/commit/edbdaff077ea0cf295b1469923c06bbccad3c180

Comment 1 Product Security DevOps Team 2023-02-08 15:31:33 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-21191