CVE-2022-21129: Command Injection
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. Note: In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-21129?
CVE-2022-21129 is a vulnerability in versions of the package nemo-appium before 0.0.9 which allows command injection due to improper input sanitization.
How severe is CVE-2022-21129?
CVE-2022-21129 has a severity rating of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-21129?
Versions of the package nemo-appium before 0.0.9 are affected by CVE-2022-21129.
How can I fix CVE-2022-21129?
To fix CVE-2022-21129, update your nemo-appium package to version 0.0.9 or above.
Where can I find more information about CVE-2022-21129?
You can find more information about CVE-2022-21129 on the GitHub page of the nemo-appium package and the security.snyk.io website.