Bug 2247069 (CVE-2023-42810) - CVE-2023-42810 systeminformation: SSID Command Injection Vulnerability
Summary: CVE-2023-42810 systeminformation: SSID Command Injection Vulnerability
Keywords:
Status: NEW
Alias: CVE-2023-42810
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2249093
TreeView+ depends on / blocked
 
Reported: 2023-10-30 14:25 UTC by Pedro Sampaio
Modified: 2023-11-14 12:52 UTC (History)
2 users (show)

Fixed In Version: systeminformation 5.21.7
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2023-10-30 14:25:08 UTC
systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to `wifiConnections()`, `wifiNetworks()` (string only).

References:

https://github.com/sebhildebrandt/systeminformation/commit/7972565812ccb2a610a22911c54c3446f4171392
https://systeminformation.io/security.html
https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-gx6r-qc2v-3p3v


Note You need to log in before you can comment on or make changes to this bug.