CVE-2021-26276: Medium severity godaddy node-config-shield vulnerability
DISPUTED scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data.
Other sources
scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26276?
CVE-2021-26276 has a disputed severity rating as the vendor states it is not a vulnerability.
How do I fix CVE-2021-26276?
To fix CVE-2021-26276, upgrade the node-config-shield package to version 0.2.3 or later.
Who is affected by CVE-2021-26276?
CVE-2021-26276 affects users of the node-config-shield package prior to version 0.2.3.
What does CVE-2021-26276 entail?
CVE-2021-26276 involves an eval call in the scripts/cli.js file when processing untrusted data with the set command.
What is the vendor's stance on CVE-2021-26276?
The vendor GoDaddy claims that the set command of node-config-shield was not intended for use with untrusted data, disputing its classification as a vulnerability.