OS Command injection in docker-cli-js
Moderate severity
GitHub Reviewed
Published
Dec 2, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Withdrawn
This advisory was withdrawn on Nov 29, 2021
Description
Published by the National Vulnerability Database
Nov 22, 2021
Withdrawn
Nov 29, 2021
Reviewed
Nov 30, 2021
Published to the GitHub Advisory Database
Dec 2, 2021
Last updated
Feb 1, 2023
Withdrawn
After reviewing this CVE, and this response from the maintainer, we have withdrawn this advisory.
Original CVE description
This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.
References