First published: Tue Mar 09 2021(Updated: )
Facebook react-dev-utils could allow a remote attacker to execute arbitrary commands on the system, caused by a flaw in getProcessForPort function. By sending a specially-crafted request, an attacker could exploit this vulnerability to inject and execute arbitrary commands on the system.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | <=2.0 | |
Facebook react-dev-utils | <11.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24033 is a vulnerability in react-dev-utils prior to v11.0.4 that exposes a function, getProcessForPort, allowing an input argument to be concatenated into a command string for execution.
The severity of CVE-2021-24033 is medium, with a severity value of 5.6.
The affected software is react-dev-utils prior to v11.0.4.
To fix CVE-2021-24033, update your react-dev-utils to version 11.0.4 or higher.
The Common Weakness Enumeration (CWE) of CVE-2021-24033 is CWE-77 and CWE-78.