VulnerabilityModified
CVE-2021-23732
If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.
CRITICAL 9.0EPSS 1.82%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- quobject/docker-cli-js
- Source
- report@snyk.io
References
- https://security.netapp.com/advisory/ntap-20211223-0004/Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DOCKERCLIJS-1568516Exploit, Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20211223-0004/Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DOCKERCLIJS-1568516Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.