Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Command Injection. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js.
Remediation
There is no fixed version for freediskspace
.
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- Credit
- John Hopkins Security Labs
- CVE
- CVE-2020-7775
- CWE
- CWE-78
- Snyk ID
- SNYK-JS-FREEDISKSPACE-1040716
- Disclosed
- 17 Nov, 2020
- Published
- 02 Feb, 2021