CVE-2021-21414: Command injection vulnerability in @prisma/sdk in getPackedPackage function
Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the @prisma/sdk package who are affected by this security vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. It only affects the getPackedPackage function and this function is not advertised and only used for tests & building our CLI, no malicious code was found after checking our codebase.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21414?
CVE-2021-21414 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2021-21414?
To mitigate CVE-2021-21414, upgrade to Prisma versions later than 2.20.0.
What software is affected by CVE-2021-21414?
CVE-2021-21414 affects the Prisma ORM versions up to and including 2.20.0.
Can CVE-2021-21414 lead to data breaches?
Yes, if exploited, CVE-2021-21414 can lead to unauthorized access and potential data breaches.
Is there a known exploit for CVE-2021-21414?
As of now, there are no publicly known exploits specifically targeting CVE-2021-21414.