First published: Tue Jan 31 2023(Updated: )
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
<0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21129 is a vulnerability in versions of the package nemo-appium before 0.0.9 which allows command injection due to improper input sanitization.
CVE-2022-21129 has a severity rating of critical with a CVSS score of 9.8.
Versions of the package nemo-appium before 0.0.9 are affected by CVE-2022-21129.
To fix CVE-2022-21129, update your nemo-appium package to version 0.0.9 or above.
You can find more information about CVE-2022-21129 on the GitHub page of the nemo-appium package and the security.snyk.io website.