CVE-2022-25350: Command Injection
Published Jan 24, 2023
·Updated
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
Affected Software
2 affected components
Helecloud Puppet-facter Node.js
npm/puppet-facter<=0.0.2
Event History
Jan 24, 2023
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Jan 26, 2023
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-25350.
2
What is the severity of CVE-2022-25350?
The severity of CVE-2022-25350 is high, with a CVSS score of 7.8.
3
What is the affected software?
The affected software is Helecloud Puppet-facter.
4
How does this vulnerability occur?
This vulnerability occurs due to improper input sanitization in the getFact function of puppet-facter.
5
Are there any references for further information about this vulnerability?
Yes, you can find more information about this vulnerability at the following references: [link-1](https://github.com/olindata/node-puppet-facter/blob/f34bcc754325d71bb3b1b534804e53d6170f15f5/index.js%23L10), [link-2](https://security.snyk.io/vuln/SNYK-JS-PUPPETFACTER-3175616).