CVE-2021-29369: OS Command Injection
Published May 3, 2021
·Updated
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.
Affected Software
1 affected component
Gnuplot Project Gnuplot Node.js<0.1.0
Remediation
Event History
May 3, 2021
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29369?
CVE-2021-29369 is classified as a high severity vulnerability due to the potential for code execution via shell metacharacters.
2
How do I fix CVE-2021-29369?
To fix CVE-2021-29369, update the gnuplot package to version 0.1.0 or later.
3
What versions of gnuplot are affected by CVE-2021-29369?
Gnuplot versions prior to 0.1.0 for Node.js are affected by CVE-2021-29369.
4
What type of attack is associated with CVE-2021-29369?
CVE-2021-29369 is associated with remote code execution attacks leveraging shell metacharacters.
5
Is CVE-2021-29369 a common vulnerability?
CVE-2021-29369 is a notable vulnerability due to its potential to allow arbitrary code execution in affected systems.